Executive brief
A security vulnerability exists in the Microsoft Office Click-to-Run service, which is responsible for installing and updating Office applications. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to bypass security restrictions, access sensitive data, or install malicious software across the organization.
Technical details
A use-after-free vulnerability (CWE-416) exists within the Microsoft Office Click-to-Run component. The flaw is triggered when the application continues to use a pointer after the memory it references has been freed, leading to memory corruption. An attacker with local access and low-level privileges can exploit this condition to execute arbitrary code with elevated system permissions. The attack requires no user interaction and has a low complexity, making it a reliable method for privilege escalation once initial access to a host is established. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Office Click-to-Run
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory