Executive brief
A vulnerability in Microsoft Office could allow an attacker to execute malicious code on a user's computer. This issue affects various versions of the productivity suite, including Office 2016 through 2024 and Microsoft 365 Apps. If exploited, an attacker could gain the same permissions as the local user, potentially leading to data theft, unauthorized system changes, or a total loss of system integrity.
Technical details
This vulnerability is classified as a Use-After-Free (CWE-416) within Microsoft Office. It occurs when the application continues to use a pointer after the memory it points to has been freed, leading to memory corruption. An attacker can exploit this by running a specially crafted application locally on the target machine. Successful exploitation grants the attacker the ability to execute arbitrary code with the privileges of the logged-in user. The vulnerability affects multiple platforms including Windows, macOS, and Android versions of the Office suite.
Affected products
- Microsoft Office 2016, 2019, 2021, 2024, 365 Apps, Copilot
Timeline
- 2025-06-10: disclosed: Initial disclosure by Microsoft and NVD publication.
- 2025-06-10: advisory: Microsoft released a vendor advisory (MSRC).