Executive brief
A security vulnerability has been identified in Microsoft Office, the widely used suite of productivity applications. This flaw could allow an attacker who has gained access to a user's computer to run malicious code with elevated permissions. Such an exploit could lead to the theft of sensitive documents, unauthorized access to corporate data, or a complete takeover of the affected workstation.
Technical details
A use-after-free vulnerability (CWE-416) exists within Microsoft Office. The flaw is triggered when the application continues to use a pointer after it has been freed, leading to memory corruption. An attacker with local access to the system can exploit this vulnerability to execute arbitrary code in the context of the current user. According to the CVSS vector, the attack requires no special privileges and no user interaction, though it must be executed locally. Microsoft has released information regarding this vulnerability via their Security Update Guide.
Affected products
- Microsoft Office
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory