Microsoft Windows Server 2012
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*
A use-after-free vulnerability has been identified in Inbox COM Objects, allowing an unauthorized attacker to execute code locally. This vulnerability arises from improper memory management, which can be exploited by sending a malicious file to the user and convincing them to open it. The issue requires navigating a race condition, adding to the complexity of successful exploitation.
Exploitation of this vulnerability allows for remote code execution on the affected system.
Users can apply the security update for this vulnerability, which is included in the October 2025 Monthly Rollup, available through the Microsoft Update Catalog.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.