Impact
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. The flaw causes an application to reference memory that has already been freed, enabling an attacker to supply crafted content that triggers this use‑after‑free and gain code execution on the victim’s machine. The weakness is categorized as CWE‑416, and the attack would grant the attacker the privileges of the logged‑in user, potentially compromising confidentiality, integrity, or availability of the system.
Affected Systems
The flaw affects several Microsoft Office and SharePoint products, including Microsoft 365 Apps for Enterprise, Office 2019, Office 2021, Office 2024, the macOS versions of Office 2019, 2021, 2024, Word 2016, and SharePoint Enterprise Server 2016, SharePoint Server 2019, SharePoint Server Subscription Edition. Only the product names are provided; no specific version details are listed. Organizations using any of these applications are potentially at risk.
Risk and Exploitability
With a CVSS score of 8.4 the vulnerability is considered high severity. The EPSS score is <1%, indicating a very low exploitation probability. The flaw is not recorded in the CISA KEV catalog, but the prevalence of Office environments means the threat remains significant. The likely attack vector is local, inferred from the description; no remote network exploitation is described. Once executed, the attacker could run arbitrary code with the current user's privileges, potentially impacting the system's confidentiality, integrity, or availability.
OpenCVE Enrichment