Impact
The vulnerability is a buffer over-read in Microsoft Office Word that enables an unauthorized local attacker to read memory contents from the application process. This can lead to the disclosure of sensitive data such as passwords, encryption keys, or personal information that resides in memory at the time of exploitation. The weakness is characterized as an Improper Handling of Buffer Boundaries (CWE‑126) and can potentially compromise confidentiality for the affected user or organization, though it does not directly affect the broader system integrity or availability.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, and Microsoft Word 2016 are the documented targets of this flaw. No specific version numbers are disclosed in the available data, and the advisory does not enumerate affected build numbers beyond the product families.
Risk and Exploitability
With a CVSS score of 5.5 the issue is considered medium severity. The exploit probability is not quantified (EPSS data is missing) and the vulnerability is not currently listed in CISA KEV, suggesting a relatively low likelihood of large‑scale exploitation. However, as the vulnerability requires local authorization and allows memory disclosure, it still poses a tangible risk to confidential data if an attacker can gain local file or user access. The likely attack vector is local execution, potentially via a specially crafted document or malicious macro that triggers the over‑read during normal Word usage.
OpenCVE Enrichment