CVE-2026-32190

8.4

Microsoft · Office

A use after free vulnerability in Microsoft Office allows an unauthorized local attacker to execute arbitrary code.

Executive summary

A critical use after free vulnerability in Microsoft Office enables local code execution, posing a significant risk of system compromise.

Vulnerability

This is a use after free flaw (CWE-416) within Microsoft Office that can be triggered by an unauthorized attacker. The vulnerability allows for local code execution, which occurs when the application attempts to access memory after it has been freed.

Business impact

The ability for an attacker to execute arbitrary code locally creates a high risk of total system compromise, including potential data theft, installation of malicious software, and unauthorized lateral movement within the network. With a CVSS score of 8.4, this vulnerability represents a severe threat to operational integrity and information security, as it bypasses standard user access controls.

Remediation

Immediate Action: Apply the latest security updates provided by Microsoft for all affected Office products immediately. Refer to the official Microsoft Security Update Guide for specific build information and download links.

Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected application crashes that may indicate exploitation attempts. Review endpoint detection and response (EDR) alerts for suspicious child processes spawned by Office applications.

Compensating Controls: Implement strict application control policies to limit the execution of unauthorized binaries. Ensure that users operate with the least privilege necessary, reducing the potential impact if a local code execution event occurs.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for full system compromise, IT administrators should prioritize the deployment of the vendor-supplied patches across all workstations and servers running the affected Microsoft Office versions. Testing and deployment should be accelerated to eliminate this critical attack vector from the environment as soon as possible.

More Microsoft CVEs

Sources