Executive brief
A security vulnerability exists in the Microsoft Office Click-to-Run service, which is responsible for installing and updating Office applications. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to bypass security restrictions, access sensitive files, or install malicious software.
Technical details
A use-after-free vulnerability (CWE-416) exists within the Microsoft Office Click-to-Run component. The flaw is triggered when the service incorrectly manages memory during specific operations, allowing an attacker to execute code with higher privileges. Exploitation requires the attacker to have local access to the system with low-level user permissions. While the attack complexity is rated as high—likely due to race conditions or specific timing requirements—a successful exploit results in a complete compromise of confidentiality, integrity, and availability (SYSTEM-level privileges). Microsoft has released security updates to address this issue.
Affected products
- Microsoft Office Click-to-Run
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory