Microsoft Office Excel Use-After-Free Vulnerability Allowing Local Code Execution
Vulnerability
A use-after-free vulnerability has been identified in Microsoft Office Excel. This issue allows an unauthorized attacker to execute code locally on the affected system. The vulnerability arises from improper memory management, which can be exploited under certain conditions.
Impact
Exploitation of this vulnerability could lead to unauthorized code execution on the affected system.
Remediation
Users can apply the security update provided by Microsoft to address this vulnerability. Instructions for downloading the security update are available on the Microsoft Update Catalog. For Microsoft Office LTSC for Mac 2021 and 2024, the security update can be downloaded via the Microsoft Update Catalog. For Microsoft 365 Apps for Enterprise, the security update is also available through the Microsoft Update Catalog. Office Online Server users can download the security update from the Microsoft Download Center.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
