CVE-2025-26630

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 11, 2025
CWE ID 416

Summary

CVE-2025-26630 is a vulnerability affecting Microsoft Office Access, where an attacker can trigger a use-after-free condition. This issue allows the adversary to execute arbitrary code locally, meaning they can manipulate the application to their advantage without requiring any network access or user interaction beyond opening a specially crafted file. This can lead to data theft, unauthorized system modifications, or even complete system compromise. Users are advised to apply the available security patch from Microsoft as soon as possible to protect against potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share