Microsoft Office
cpe:2.3:a:microsoft:office:*:*:*:*:*:*:*, +8 more
A use-after-free vulnerability has been identified in Microsoft Office, which allows an unauthorized attacker to execute code locally. This vulnerability requires the attacker to log onto the system and can be exploited by running a specially crafted application or by convincing a local user to open a malicious file. The vulnerability is present in several versions of Microsoft Office, including Office 2016, Office 2019, Office 2021, and various editions of Office LTSC for Mac.
Exploitation of this vulnerability could lead to unauthorized local code execution on the affected system.
Security updates for this vulnerability are available for Microsoft Office LTSC for Mac 2021 and 2024. Customers should ensure these updates are installed. For other Microsoft Office versions, no action is required.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.