Executive brief
A vulnerability in Microsoft Office could allow an attacker to run malicious code on a user's computer. This typically occurs if a user is tricked into opening a specially crafted file. Successful exploitation could lead to a full compromise of the user's data, unauthorized access to corporate resources, or the installation of malware.
Technical details
A use-after-free (CWE-416) vulnerability exists in multiple versions of Microsoft Office, including desktop and Android editions. The flaw is triggered when the application continues to use a pointer after it has been freed, leading to memory corruption. An attacker can exploit this by convincing a user to open a malicious file, resulting in local code execution with the privileges of the current user. The attack vector is local with a requirement for user interaction (UI:R). Microsoft has released security updates to address this issue across affected platforms.
Affected products
- Microsoft Office 2016
- Microsoft Office 2019
- Microsoft Office LTSC 2021
- Microsoft Office LTSC 2024
- Microsoft 365 Apps for Enterprise
- Microsoft Office for Android versions prior to 16.0.19328.20000
Timeline
- 2025-10-14: disclosed
- 2025-10-14: advisory: MSRC advisory published