Impact
Microsoft Office Word contains a buffer over‑read that allows an unauthorized local attacker to disclose sensitive data from memory. The flaw is an instance of CWE‑126 "Improper Buffer Access before Length Validation" and its exploitation enables a confidentiality breach by leaking information from the Office process. The impact is limited to local files and does not provide unauthorized code execution or system compromise.
Affected Systems
The vulnerability affects Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, and Microsoft Word 2016. These product lines include both 32‑bit and 64‑bit editions across the specified releases.
Risk and Exploitability
With a CVSS score of 5.5 the severity is moderate. No EPSS data is available, and the vulnerability is not listed in CISA KEV. The attack vector is local; an adversary must gain local access to the affected machine and execute a crafted document. Because the flaw does not involve remote interaction, the likelihood of widespread exploitation is limited to environments where local privileges are mis‑managed.
OpenCVE Enrichment