CVE-2025-53738

7.8

Microsoft · Microsoft Office Word

A use after free vulnerability in Microsoft Office Word allows an unauthorized attacker to achieve local code execution.

Executive summary

A critical use after free vulnerability in Microsoft Office Word could allow an unauthorized attacker to execute arbitrary code locally on a target system.

Vulnerability

This is a use after free vulnerability (CWE-416) within Microsoft Office Word. The flaw occurs during memory management processes, and while it requires user interaction, it does not require prior authentication to trigger.

Business impact

Successful exploitation of this vulnerability permits an attacker to execute code locally with the privileges of the logged in user. This represents a significant security risk that could lead to full system compromise, unauthorized data access, or the installation of persistent malicious software. Given the CVSS score of 7.8, this is classified as a high severity issue requiring prompt attention to prevent potential lateral movement within the network.

Remediation

Immediate Action: Organizations must apply the latest security updates provided by Microsoft immediately, as detailed in the official Microsoft Security Update Guide.

Proactive Monitoring: Security teams should monitor endpoint logs for suspicious child processes spawned by Microsoft Word and investigate any unusual memory access patterns or unexpected application crashes.

Compensating Controls: Ensure that attack surface reduction rules are enabled on endpoints to block Office applications from creating child processes, which can mitigate the impact of code execution attempts.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The severity of this vulnerability, combined with the potential for local code execution, mandates that all affected systems be patched as soon as possible. Administrators should prioritize the deployment of the provided vendor updates across all enterprise workstations to neutralize this risk and ensure continued system integrity.

More Microsoft CVEs

Sources