Executive brief
A vulnerability in Microsoft Office could allow an attacker to execute malicious code on a user's computer. This typically occurs when a user is tricked into opening a specially crafted file, potentially leading to a full system compromise, data theft, or unauthorized software installation. Microsoft Office is a standard suite of productivity tools used globally for document creation and business operations.
Technical details
A use-after-free (CWE-416) vulnerability exists in multiple versions of Microsoft Office, including Office 2016, 2019, LTSC 2021, LTSC 2024, and Microsoft 365 Apps. The flaw is triggered when the application continues to use a pointer after it has been freed, which can be exploited to achieve arbitrary code execution. The attack vector is local, but it requires user interaction, such as a victim opening a malicious document. Successful exploitation allows an attacker to execute code with the same privileges as the current user. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise 16.0.1 and later
- Microsoft Microsoft Office 2016 16.0.0 up to 16.0.5561.1000
- Microsoft Microsoft Office 2019 19.0.0 and later
- Microsoft Microsoft Office LTSC 2021 16.0.1 and later
- Microsoft Microsoft Office LTSC 2024 16.0.0 and later
Timeline
- 2026-07-14: disclosed: Initial disclosure by Microsoft Corporation
- 2026-07-14: advisory: NVD entry published