CVE-2025-24077
Published: 11 March 2025
Description
Adversaries may exploit software vulnerabilities in client applications to execute code.
Security Summary
CVE-2025-24077 is a use-after-free vulnerability (CWE-416) affecting Microsoft Office Word. Published on 2025-03-11, it carries a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). The flaw enables an unauthorized attacker to execute code locally on a victim's machine.
Exploitation requires local access to the target system and user interaction, such as opening a malicious document, with low attack complexity and no special privileges needed from the attacker. Successful exploitation grants high-impact arbitrary code execution, compromising confidentiality, integrity, and availability.
The Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24077 details mitigation steps and available patches.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
Use-after-free in Microsoft Word enables arbitrary code execution via crafted malicious document opened by user, directly mapping to Exploitation for Client Execution.