Over the weekend, a Proof-of-Concept for the vulnerability, (also known as CVE-2023-21716), which exposed a critical “RCE bug” in Microsoft Word that allows remote code execution.
This vulnerability received a “severity” rating of 9.8 out of 10, and Microsoft addressed it in February’s monthly security updates (Patch Tuesday), along with some workarounds.
Proof-of-Concept is a practice in which work is focused on determining whether an idea can be turned into reality.
See also: Outdated Windows UAC Bypass Allows Phishing Campaigns

The vulnerability could be used by a remote attacker to execute code with the same privileges as the same victim who opens a malicious .RTF document.
Microsoft warns that simply loading the file in the Preview Pane to initiate the breach, and that users do not need to open a specific malicious RTF document.
This "sensitivity" is caused by a heap corruption vulnerability that is triggered when processing a font table (*\fonttbl*) that contains an excessive number of fonts (*\f###*).
A properly crafted heap layout can be used to exploit the flaw to execute arbitrary code.

There is currently no evidence that the vulnerability is actually being used, but critical vulnerabilities like this one attract the attention of threat actors, with the more experienced trying to reverse engineer the fix to find a way to exploit it.
Microsoft recommends installing the latest security updates to address this vulnerability
There are workarounds available, such as reading emails in plain text or enabling File Block , which requires modifying the Windows Registry.
It is currently unclear whether the Proof-of-Concept can be weaponized for a full-fledged exploit, but an RCE “attack” on Microsoft Word could lead to a massive spread of malware via emails.
Source: bleepingcomputer.com
