Microsoft Office Use-After-Free Vulnerability Allowing Local Remote Code Execution

Vulnerability

A use-after-free vulnerability has been identified in Microsoft Office, which allows an unauthorized attacker to execute code locally. This vulnerability is present in several different versions of Microsoft Office.

Impact

Exploitation of this vulnerability could lead to remote code execution on the affected system.

Remediation

Microsoft has released security updates for May 2025 addressing this vulnerability. Users should ensure they have the latest build installed. For more information, visit the Microsoft Office Update Guide.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
10.0
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.