Impact
This vulnerability is a use‑after‑free flaw in Microsoft Word that permits an attacker to run arbitrary code locally on a victim machine. Marked as CWE‑416, the flaw arises when Word permits a memory reference to a freed object to be dereferenced. Because the code runs under the current user’s privilege, an attacker can achieve execution of malicious payloads, compromise data integrity, and potentially elevate privileges if the user holds elevated rights.
Affected Systems
Affected are Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Word 2016. The CVE data does not specify sub‑versions, but all editions listed are impacted.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, indicating a high risk if exploitable. EPSS indicates a very low likelihood of attack, and the flaw has not appeared in CISA’s KEV catalog. The likely attack vector requires the victim to open a specially crafted document, so remote exploitation would typically happen through social engineering or phishing. An attacker who can deliver the malicious document can invoke the use‑after‑free and execute code locally.
OpenCVE Enrichment