Impact
A heap‑based buffer overflow exists in Microsoft Word that lets an attacker craft a malicious document and trigger code execution when the document is processed. The flaw originates from improper bounds checking before memory allocation (CWE-122). Successful exploitation would allow the attacker to run arbitrary code with the privileges of the document viewer, potentially compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects multiple Microsoft Office products, including Microsoft 365 Apps for Enterprise, Microsoft Office 2016, 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, and the corresponding Mac editions. All mentioned Windows and macOS versions are susceptible when they have not received the recent security update.
Risk and Exploitability
The CVSS score of 8.8 classifies the flaw as high severity. The EPSS score is not available, so the current exploitation probability cannot be quantified from this source. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote: a network‑bound attacker can deliver a crafted document to a victim’s computer and force the vulnerable component to execute code, resulting in full remote code execution.
OpenCVE Enrichment