Executive brief
A security vulnerability has been identified in Microsoft Office, the widely used suite of productivity applications. If exploited, this flaw could allow an attacker to execute malicious code on a user's computer, potentially leading to full system compromise or data theft. The attack requires a user to open a specially crafted file, making it a significant risk for phishing or targeted social engineering campaigns.
Technical details
This vulnerability is classified as a Use-After-Free (CWE-416) within Microsoft Office. The flaw is triggered when the application attempts to access memory that has already been freed, which can be exploited to achieve local code execution. The attack vector is local, but it requires user interaction (UI:R), typically involving a victim opening a malicious document. The vulnerability affects multiple versions of Office across both Windows and macOS platforms. Microsoft has released security updates to address this issue, and users are advised to apply the latest patches for their specific Office version.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise 16.0.1 up to security releases
- Microsoft Microsoft Office 2016 16.0.0 to 16.0.5561.1000
- Microsoft Microsoft Office 2019 19.0.0 up to security releases
- Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 16.0.1 up to security releases
- Microsoft Microsoft Office LTSC 2024 16.0.0 up to security releases
- Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
- Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory