Executive brief
A security vulnerability has been identified in Microsoft Office, the widely used suite of productivity applications. An attacker who already has basic access to a computer could exploit this flaw to gain higher-level system permissions. This could allow them to bypass security restrictions, access sensitive data, or install malicious software that would otherwise be blocked.
Technical details
A use-after-free vulnerability (CWE-416) exists within Microsoft Office. The flaw is triggered when the application continues to use a pointer after the memory it references has been freed, leading to memory corruption. An attacker with local access and low-privileged user credentials can exploit this to execute code with elevated privileges. The attack vector is local, requiring no user interaction, and provides high impact to confidentiality, integrity, and availability. Microsoft has released information regarding this vulnerability in their security update guide.
Affected products
- Microsoft Office
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: Microsoft published the security update guide for this vulnerability.