Microsoft Office
cpe:2.3:a:microsoft:office:*:*:*:*:-:*:*
A vulnerability allowing out-of-bounds read has been identified in Microsoft Office. This issue could enable an unauthorized attacker to locally disclose information by reading small portions of heap memory. The vulnerability affects multiple versions of Microsoft Office, including Office 2016, Office 2019, Office LTSC 2021, Office LTSC 2024, and various SharePoint Server products.
Exploitation of this vulnerability could lead to unauthorized information disclosure.
Users can download the security update for Microsoft Office 2016 (both 32-bit and 64-bit editions) from the Microsoft Update Catalog. For Microsoft Office LTSC 2021 and 2024 for Mac, the security updates will be released as soon as possible, with customers being notified via a revision to the CVE information. Microsoft 365 Apps for Enterprise users can also download the security update from the Microsoft Update Catalog. SharePoint Server users can download the security update from the Microsoft Update Catalog as well.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.