CVE-2025-24082
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Mar 11, 2025
CWE ID 416
Summary
CVE-2025-24082 is a use-after-free vulnerability impacting Microsoft Office Excel. An attacker can exploit this flaw to execute malicious code locally, gaining unauthorized access to a victim's system. The issue occurs when Excel fails to properly manage memory, allowing an attacker to manipulate uninitialized memory and inject their own code. This vulnerability poses a significant risk, particularly in enterprise environments where Excel is widely used, and requires immediate attention from IT teams and users to apply patches or mitigations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.