Microsoft Office Excel Use-After-Free Vulnerability Allowing Local Code Execution

Vulnerability

A use-after-free vulnerability has been identified in Microsoft Office Excel. This issue allows an unauthorized attacker to execute code locally on the affected system. The vulnerability arises from improper memory management, which can be exploited to manipulate the program's execution flow.

Impact

Exploitation of this vulnerability could lead to unauthorized local code execution within the context of the user running Excel.

Remediation

Security updates addressing this vulnerability are available for Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft 365 Apps for Enterprise (32-bit and 64-bit), and Microsoft Office LTSC 2021 (32-bit and 64-bit). Users should ensure these updates are installed. For Microsoft Office LTSC for Mac 2021 and 2024, the security update is available as of May 14, 2025.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.