Impact
Use‑after‑free in Microsoft Office permits an attacker to execute code locally. The flaw, a CWE‑416 vulnerability, can lead to arbitrary code execution within the Office process, potentially compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
Affecting Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Office for Android with no specific versions listed.
Risk and Exploitability
The EPSS score of < 1% indicates a low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local execution, requiring that an attacker can trigger Office to process malformed input, but the exact trigger is not detailed in the CVE data. While user interaction is not explicitly described, potential impact is significant due to the possibility of arbitrary code execution.
OpenCVE Enrichment