Impact
A classic double‑free flaw in Microsoft Office Word allows an unauthorized attacker to supply a specially crafted document that causes Word to release a memory block twice. The result is arbitrary code execution with the privileges of the user who opens the file, thereby compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects a broad range of Microsoft Office product lines for both Windows and macOS, including Microsoft 365 Apps for Enterprise, Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, Office LTSC for Mac 2024, and Microsoft Word 2016. All supported editions of these products are presumed vulnerable; no specific version ranges are provided in the advisory.
Risk and Exploitability
With a CVSS score of 8.8, the flaw is high severity and can be exploited over a network when a malicious document is opened. The EPSS score is not available, so exploitation frequency cannot be precisely determined. The condition that the flaw is not listed in the CISA KEV catalog suggests no widespread public exploitation to date, yet the ability to execute code remotely without user interaction makes it a serious threat for enterprises. The most likely attack vector is delivery of a crafted Word file via email, shared drives, or web download, which the victim then opens in Office.
OpenCVE Enrichment