PT-2025-15568 · Microsoft · Office
0X140Ce
+1
·
Published
2025-04-08
·
Updated
2025-04-15
·
CVE-2025-27745
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Office (affected versions not specified)
Description
The issue is related to a use after free vulnerability in Microsoft Office, which allows an unauthorized attacker to execute code locally. This vulnerability can be exploited by remote attackers to execute arbitrary code and affect the system. The vulnerability is associated with the use of memory after it has been freed.
Recommendations
For Microsoft Office for Mac, customers should install the available security update to be protected from this vulnerability.
For other Microsoft Office software, no action is required.
As a temporary workaround, consider disabling any functionality that may be using the vulnerable memory allocation until a patch is available.
At the moment, there is no information about specific versions that contain a fix for this vulnerability, but installing the latest security updates for Microsoft Office for Mac is recommended.
Fix
RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office