Junglewise Threat Intelligence

CVE-2026-50314: Microsoft Office use after free code execution

CVE-2026-50314 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Office, a widely used suite of productivity applications. If exploited, this flaw could allow an attacker to execute malicious code on a user's computer, potentially leading to unauthorized data access or full system compromise. The attack requires a user to open a specially crafted file, making it a significant risk for phishing or targeted social engineering campaigns.

Technical details

This vulnerability is classified as a Use-After-Free (CWE-416) within Microsoft Office. The flaw occurs when the application continues to use a pointer after it has been freed, which can be leveraged by an attacker to corrupt memory and execute arbitrary code. The attack vector is local, but it requires user interaction (UI:R), typically involving a victim opening a malicious document. The vulnerability affects multiple versions of Office across both Windows and macOS platforms. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise 16.0.1 up to security release
  • Microsoft Microsoft Office 2016 16.0.0 to 16.0.5561.1000
  • Microsoft Microsoft Office 2019 19.0.0 up to security release
  • Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 16.0.1 up to security release
  • Microsoft Microsoft Office LTSC 2024 16.0.0 up to security release
  • Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
  • Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215

Timeline

  • 2026-07-14: advisory: Initial publication by Microsoft and NVD
  • 2026-07-14: patched: Security updates made available via Microsoft Update Guide

References

Related threats