Impact
A double free flaw in Microsoft Office Word allows an unauthorized attacker to execute arbitrary code on the target system. The vulnerability results from a memory corruption bug that causes the same memory region to be freed twice, enabling manipulation of program flow by an attacker who can provide a specially crafted Office document or payload over the network.
Affected Systems
The affected products are Microsoft Windows 10 (v1607, v1809, v21H2, v22H2), Windows 11 (v23H2, v24H2, v25H2, v26H1), and Microsoft Windows Server 2012, Server 2012 (Server Core), Server 2012 R2, Server 2012 R2 (Server Core), Server 2016, Server 2016 (Server Core), Server 2019, Server 2022, and Server 2025 (including Server Core).
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. EPSS is not available, but the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is network-based, with an attacker delivering a malicious Office document or enabling exploit code through a remote channel. Successful exploitation would give the attacker full code execution privileges on the affected system, potentially compromising confidentiality, integrity, and availability.
OpenCVE Enrichment