Impact
Microsoft Office contains a use‑after‑free flaw that can be triggered by an unauthorized attacker to execute arbitrary code locally on the machine. The vulnerability arises from improper memory handling within the Office application, allowing the attacker to run code with the privileges of the current user. This leads to full compromise of confidentiality, integrity, and availability of the affected system, and is listed under CWE‑416.
Affected Systems
The following products are affected: Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. All listed editions carry the vulnerability; specific version ranges are not detailed in the current data.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, but the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not listed in CISA’s KEV, so no confirmed public exploits are known. Based on the description, the likely attack vector is local exploitation, such as opening a malicious Office document or file that triggers the use‑after‑free condition. No network‑based attack path is indicated by the available information.
OpenCVE Enrichment