Impact
This vulnerability is a heap‑based buffer overflow (CWE‑122) that enables an attacker to read arbitrary data from memory. The flaw occurs when Office processes certain inputs, causing the application to access memory beyond intended bounds and potentially expose confidential information. The disclosed data can include sensitive configuration or organizational secrets, compromising the confidentiality of the affected system.
Affected Systems
The flaw affects multiple Microsoft Office product lines: Microsoft 365 Apps for Enterprise, Office 2016, Office 2019, Office 2021 LTSC, Office 2024 LTSC, Office 365 for Mac, and the long‑term servicing channel releases for macOS 2021 and 2024.
Risk and Exploitability
The CVSS score of 6.5 characterizes this vulnerability as moderate severity. EPSS data is not available, so the exact exploitation probability cannot be quantified, and the flaw is not listed in the CISA KEV catalog. Based on the description, no user interaction is explicitly required; the attacker likely exploits the flaw via a remote network scenario, delivering a crafted payload that Office processes and triggering the heap overflow.
OpenCVE Enrichment