Impact
An out‑of‑bounds read bug in Microsoft Office Word permits an attacker to read memory beyond the allocated boundaries, revealing confidential data. This flaw is classified as CWE‑125 and carries a CVSS score of 6.5, indicating a moderate severity that can compromise the confidentiality of document contents and application memory.
Affected Systems
Impact covers Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. Any version of these products is affected, with no further sub‑release details provided.
Risk and Exploitability
The CVSS score of 6.5 highlights a moderate risk of exploitation. The description indicates that the read can be triggered over a network, so the likely attack vector is remote network‑based. The vulnerability is not listed in the CISA KEV catalog, implying limited known exploitation, yet any machine that runs the affected Office versions and receives untrusted documents could be at risk if an attacker controls the network traffic.
OpenCVE Enrichment