Microsoft Office Excel Use-After-Free Vulnerability Allowing Local Code Execution
Vulnerability
A use-after-free vulnerability has been identified in Microsoft Office Excel. This issue allows an unauthorized attacker to execute code locally on the affected system. The vulnerability arises from improper memory management, which can be exploited to manipulate the program's execution flow.
Impact
Exploitation of this vulnerability could lead to unauthorized local code execution within the context of the user running Excel.
Remediation
Security updates addressing this vulnerability are available for Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft 365 Apps for Enterprise (32-bit and 64-bit), and Microsoft Office LTSC 2021 (32-bit and 64-bit). Users should ensure these updates are installed. For Microsoft Office LTSC for Mac 2021 and 2024, the security update is available as of May 14, 2025.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
