PT-2025-10846 · Microsoft · Office Access
Published
2025-03-11
·
Updated
2025-07-03
·
CVE-2025-26630
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Microsoft Office Access versions prior to the fixed version
Description:
The issue is related to a use-after-free vulnerability in Microsoft Office Access, which allows an unauthorized attacker to execute code locally. This vulnerability can be exploited by remote attackers to execute arbitrary code and affect the system. The recent updates for Windows 11, identified as KB5053598 and KB5053602, have addressed this vulnerability along with six other zero-day vulnerabilities and 57 other flaws. The updates bring improvements to various features, including taskbar enhancements, Windows Spotlight, and accessibility features. However, there are known issues with audio concerns and compatibility challenges involving certain drivers and software.
Recommendations:
As a temporary workaround, consider disabling the vulnerable component in Microsoft Office Access until a patch is available.
Update to the latest version of Microsoft Office Access that includes the fix for this vulnerability.
Apply the updates KB5053598 and KB5053602 for Windows 11 to address the vulnerability and other security concerns.
Restrict access to the vulnerable module in Microsoft Office Access to minimize the risk of exploitation.
Fix
RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office Access