Impact
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. By triggering this flaw, the attacker can run code with the privileges of the logged‑in user, potentially compromising confidentiality, integrity, or availability of the system. This flaw is classified as CWE‑416.
Affected Systems
The flaw affects Microsoft 365 Apps for Enterprise, Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, Office LTSC for Mac 2024, Word 2016, SharePoint Enterprise Server 2016, SharePoint Server 2019, SharePoint Server Subscription Edition. No specific version details are listed. Organizations using any of these are potentially at risk.
Risk and Exploitability
With a CVSS score of 8.4 the vulnerability is considered high severity. The EPSS score is <1%, indicating a very low exploitation probability. The flaw is not recorded in the CISA KEV catalog, but the prevalence of Office environments means the vector is local, inferred from the description; no remote network exploitation is described. Once executed, the attacker could run arbitrary code with the current user’s privileges, potentially impacting the system’s confidentiality, integrity, or availability.
OpenCVE Enrichment