Microsoft Office Use-After-Free Vulnerability Allowing Local Code Execution

Vulnerability

A use-after-free vulnerability has been identified in Microsoft Office, which allows an unauthorized attacker to execute code locally. This vulnerability requires user interaction, as the attacker must send a malicious file that the user needs to open. The Preview Pane can also be used to exploit this vulnerability.

Impact

Exploitation of this vulnerability could lead to unauthorized local code execution.

Remediation

Users can download the security update for this vulnerability through the Microsoft Update Catalog. For Microsoft Office 2016, the security update is available via the Microsoft Download Center.

Added: Oct 14, 2025, 6:21 PM
Updated: Oct 14, 2025, 8:47 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
10.0
exploitability
4.4
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.