Impact
A use‑after‑free flaw in Microsoft Office allows an attacker to run arbitrary code when Office processes a specially crafted document or file. The vulnerability is a classic CWE‑416 condition that can lead to complete compromise of the affected user’s machine, allowing the attacker to steal data, tamper with files, or launch further attacks. The impact is local code execution with the potential to affect confidentiality, integrity, and availability of the victim’s environment.
Affected Systems
The flaw affects Microsoft‑issued Office products, including Microsoft 365 Apps for Enterprise, Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, and Office LTSC for Mac 2024. These are deployed across Windows and macOS platforms regardless of the servicing channel. No specific version ranges were supplied in the CNA data, so any installation of these products is potentially vulnerable.
Risk and Exploitability
With a CVSS score of 7.8, the vulnerability is classified as high severity. The EPSS score is < 1%, indicating a low probability of exploitation, and the vulnerability is not a current entry in CISA’s KEV catalog. The likely attack vector is document or file‑based; an attacker can deliver a malicious file that triggers the use‑after‑free in Office, giving them local execution on a target system that has not patched or restricted Office document handling.
OpenCVE Enrichment