Impact
The vulnerability is a use‑after‑free flaw (CWE‑416) in Microsoft Office that can be leveraged by an attacker to execute arbitrary code on a victim’s machine. The CVE description explicitly states that the use‑after‑free allows an unauthorized attacker to execute code locally. It does not define a specific trigger, but typical Office exploitation scenarios involve processing a crafted or maliciously formatted document, macro, or embedded object, which would require the Office application to be invoked with the vulnerable file.
Affected Systems
Affected products span several Microsoft Office suites, including the 365 Apps for Enterprise, Office 2016, 2019, LTSC 2021 and 2024, Office 365 for Mac, and the LTSC for Mac 2021 and 2024 editions. The flaw lies in the Office binary executed on the Windows or macOS operating systems, as reflected by the vendor list and CPE entries.
Risk and Exploitability
The CVSS score of 7.8 classifies this vulnerability as high severity, and it is a local code‑execution vulnerability that grants the attacker the privileges of the Office process (typically the user). The EPSS score of less than 1 % indicates a low likelihood of exploitation in the wild, and the vulnerability is not currently catalogued in CISA's KEV list. Because the flaw requires the Office application to process a triggering input, the most probable attack vector is a local user interaction or a delivered malicious file that Office processes. This vector is inferred from typical Office behavior, as the CVE description does not specify a precise trigger.
OpenCVE Enrichment