Microsoft Office LTSC 2024
cpe:2.3:a:microsoft:office_long_term_servicing_channel:*:*:*:*:*:*:*, +2 more
A use-after-free vulnerability has been identified in Microsoft Office, which allows an unauthorized attacker to execute code locally. This vulnerability requires user interaction, as the attacker must send a malicious file that the user needs to open. The Preview Pane can also be used to exploit this vulnerability.
Exploitation of this vulnerability could lead to unauthorized local code execution.
Users can download the security update for this vulnerability through the Microsoft Update Catalog. For Microsoft Office 2016, the security update is available via the Microsoft Download Center.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.