Impact
The flaw is an out‑of‑bounds read in Microsoft Office Outlook that allows an attacker who is not privileged to extract data beyond the intended memory boundaries. Once triggered, the attacker can view sensitive information that resides in the victim’s memory space, potentially exposing confidential documents, credentials, or other private data.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, and Microsoft Office LTSC 2024 are affected. No specific sub‑versions are listed, so all releases of these products are potentially vulnerable unless patched.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, indicating a moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote network attacker who sends specially crafted content to Outlook—such as an email attachment or corrupted file—to exploit the out‑of‑bounds read. Because the flaw is triggered by external input, mitigations that enforce strict bounds checking or isolation of the Outlook process reduce risk.
OpenCVE Enrichment