Impact
The vulnerability is an out‑of‑bounds read (CWE‑125) that permits an attacker to read protected memory. Successful exploitation could lead to the disclosure of sensitive information over the network, compromising confidentiality. The description indicates the defect arises during document processing, where memory bounds are not correctly enforced, allowing unauthorized memory access.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. All licensed versions of these products may be affected; applying the latest security updates is required.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate level of impact. The EPSS score is not available and no external exploitation reports are known, indicating a low to moderate immediate risk. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, requiring a user to open or preview a malicious Office document to trigger the out‑of‑bounds read and exfiltrate data over the network.
OpenCVE Enrichment