Executive brief
Microsoft Office is widely used across organizations for document creation, editing, and collaboration. A use-after-free vulnerability in Office could allow an attacker with local system access to execute arbitrary code with elevated privileges, potentially leading to complete system compromise, data theft, or malware installation.
Technical details
A use-after-free memory vulnerability exists in Microsoft Office that allows an attacker with local access to trigger code execution. The vulnerability occurs when the Office application references memory that has already been freed, allowing an attacker to control program flow and execute arbitrary code. Exploitation requires local access to the system and does not require user interaction beyond opening a malicious Office document. An attacker can achieve arbitrary code execution in the context of the Office application. Patches are available through Microsoft's Security Update Guide.
Affected products
- Microsoft Office
Timeline
- 2026-08-11: disclosed