Impact
Microsoft Office contains an out-of-bounds read bug that enables an attacker to read memory contents that are not intended for normal use, resulting in the disclosure of sensitive data. The flaw does not provide direct code execution or denial‑of‑service capabilities, but it undermines confidentiality by leaking potentially private information that resides in Office process memory.
Affected Systems
The vulnerability applies to Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. These include both Windows and macOS deployments across the listed editions and servicing channels.
Risk and Exploitability
With a CVSS score of 6.5 the flaw is considered moderate; the EPSS score is not available and the issue is not listed in CISA KEV. The description notes that the disclosure can occur over a network, suggesting that an unauthorized user who can interact with an Office session—such as via phishing or malicious documents—may trigger the read. While the path to exploitation is not fully articulated, the moderate severity and lack of publicly available exploits imply that the risk remains primarily limited to environments where Office is running with insufficient network segmentation or who may inadvertently process untrusted content.
OpenCVE Enrichment