Executive brief
A vulnerability has been identified in Microsoft Office, the widely used suite of productivity applications. This flaw could allow an attacker who has gained access to a user's device to execute malicious code with elevated permissions. Such an exploit could lead to the theft of sensitive documents, unauthorized access to corporate data, or a complete compromise of the affected workstation.
Technical details
A use-after-free (UAF) vulnerability exists within Microsoft Office due to improper memory management. An attacker with local access to a system can exploit this flaw to execute arbitrary code in the context of the current user without requiring prior administrative privileges or user interaction. The vulnerability affects multiple versions of Office, including Office 2016, 2019, LTSC 2021, LTSC 2024, Microsoft 365 Apps, and Office for Android. Successful exploitation results in a complete loss of confidentiality, integrity, and availability. Microsoft has released security updates to address this issue via the MSRC Update Guide.
Affected products
- Microsoft Office 2016, 2019, 2021, 2024, 365 Apps, Android
Timeline
- 2025-06-10: disclosed
- 2025-06-10: advisory: Published by Microsoft and NVD