Impact
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. It does not require authentication and can be triggered by opening a malicious Office document, leading to code execution within the user's process space under the same privileges. This can enable lateral movement or privilege escalation. The flaw corresponds to CWE‑416, a use‑after‑free weakness.
Affected Systems
The flaw affects a broad array of Microsoft Office products across Windows, macOS, and Android, including Microsoft 365 Apps for Enterprise, Office 2016, Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, Office LTSC for Mac 2024, and Office for Android. Version specifics are not listed but any current releases in these product families are considered potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.4 classifies this vulnerability as high severity, while the EPSS score of < 1% indicates that exploitation is considered unlikely but not impossible. The likely attack vector is inferred to be local; an unauthenticated user must open a malicious Office document to trigger the flaw. Successful exploitation would give the attacker code execution within the user's session, which could be leveraged for lateral movement or privilege escalation depending on the target environment.
OpenCVE Enrichment