Impact
A heap‑based buffer overflow in Microsoft Office Word can let an unauthorized attacker execute arbitrary code when the vulnerable application processes a crafted document received over a network. The flaw maps to CWE‑122, a classic heap overflow that permits attackers to take control of the victim system, potentially compromising confidentiality, integrity, and availability of the host.
Affected Systems
The vulnerability affects Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Word 2016. No specific version numbers are listed, so all current releases of the mentioned products appear at risk.
Risk and Exploitability
With a CVSS score of 8.8 the flaw is rated high severity. No EPSS data is available, but the lack of a KEV listing does not reduce the likelihood that attackers will target it. The flaw is typically exploitable remotely by delivering a malicious Office file, for example via email or a shared network location, and relies on the victim's Office application processing that file.
OpenCVE Enrichment