Impact
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally on the victim's system. The flaw occurs when memory that has already been freed is accessed again, corresponding to CWE-416, and permits arbitrary code execution that can compromise confidentiality, integrity, and availability.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Office for Android.
Risk and Exploitability
Based on the description, it is inferred that an attacker could leverage this use‑after‑free to run arbitrary code locally whenever the Office application processes the vulnerable memory state. The CVSS score of 8.4 indicates high severity. The EPSS score is under 1% and the vulnerability is not listed in KEV, suggesting a low probability of exploitation. Immediate attention is warranted to reduce risk.
OpenCVE Enrichment