Junglewise Threat Intelligence

CVE-2026-50467: Microsoft Office use after free local code execution

CVE-2026-50467 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Office, the widely used suite of productivity applications. An attacker could exploit this flaw to run unauthorized code on a user's computer if the user is tricked into opening a specially crafted file. This could lead to a full compromise of the user's data, unauthorized access to corporate resources, and disruption of business operations.

Technical details

A Use-After-Free (UAF) vulnerability exists in Microsoft Office across multiple versions, including Office 2016, 2019, LTSC, and Microsoft 365 Apps. The flaw is triggered when the application attempts to use memory that has already been freed, which can be leveraged by an attacker to achieve arbitrary code execution. The attack vector is local, requiring a user to interact with a malicious file (User Interaction: Required). Successful exploitation allows the attacker to execute code with the privileges of the logged-in user. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise 16.0.1 to latest security release
  • Microsoft Microsoft Office 2016 16.0.0 to 16.0.5561.1000
  • Microsoft Microsoft Office 2019 19.0.0 to latest security release
  • Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 16.0.1 to latest security release
  • Microsoft Microsoft Office LTSC 2024 16.0.0 to latest security release
  • Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
  • Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats