Microsoft Office
cpe:2.3:a:microsoft:office:*:*:*:*:*:*:*, +1 more
A use-after-free vulnerability has been identified in Microsoft Office, which allows an unauthorized attacker to execute code locally. This vulnerability affects several versions of Microsoft Office, including Office 2016, Office 2019, Office 2021, and various editions of Office LTSC for Mac. The vulnerability arises from improper memory management, which can be exploited to execute arbitrary code.
Exploitation of this vulnerability could lead to unauthorized local code execution.
Users can download the security update for this vulnerability through the Microsoft Update Catalog or via the Click-to-Run service for Microsoft 365 Apps. For Microsoft Office LTSC for Mac 2021 and 2024, the security update is available as of April 14, 2025.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.