Junglewise Threat Intelligence

CVE-2025-59234: Microsoft Office use after free local code execution

CVE-2025-59234 · Severity: high · CVSS 7.8 · Published 2025-10-14

Technologies: Microsoft Office, Microsoft 365 Copilot. Vendors: Microsoft.

Executive brief

A vulnerability in Microsoft Office could allow an attacker to run malicious code on a user's computer. This typically occurs if a user is tricked into opening a specially crafted file. Successful exploitation could lead to a full compromise of the user's documents, data, and system access.

Technical details

A use-after-free (CWE-416) vulnerability exists in multiple versions of Microsoft Office, including desktop and mobile (Android) editions. The flaw is triggered when the application attempts to use memory that has already been freed, which can be leveraged by an attacker to execute arbitrary code. While the attack vector is local, it requires user interaction, such as opening a malicious document. The vulnerability affects Office 2016, 2019, LTSC 2021/2024, and Microsoft 365 Apps across Windows, macOS, and Android platforms. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Office 2016, 2019, LTSC 2021, LTSC 2024, 365 Apps, Android versions before 16.0.19328.20000
  • Microsoft 365 Copilot Android versions before 16.0.19328.20000

Timeline

  • 2025-10-14: disclosed
  • 2025-10-14: advisory

References

Related threats