CVE-2025-26630 Details
Description
Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally.
A use-after-free vulnerability has been identified in Microsoft Office Access. This vulnerability allows an unauthorized attacker to execute code locally. It affects several different versions and editions of Microsoft Office Access, including the 2016 32-bit and 64-bit editions, as well as the Office LTSC 2024 and 2021 versions for both 32-bit and 64-bit systems. Additionally, Microsoft 365 Apps for Enterprise in both 32-bit and 64-bit systems are affected. The vulnerability arises from a use-after-free memory error, which can be exploited by convincing a user to open a malicious file.
Users can apply the security update provided by Microsoft to address this vulnerability. This security update is available through the Microsoft Update Catalog for Office 2016 users, and via the Click-to-Run service for Microsoft 365 Apps for Enterprise, Office LTSC 2024, Office LTSC 2021, and Office 2019 users.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26630 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft 365 apps | All versions |
CPE
Remediation
| |
| microsoft access | 2016 |
CPE
Remediation
| |
| microsoft office | 2019 |
CPE
Remediation
| |
| microsoft office long term servicing channel | 2021 2024 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 3, 2025 | Initial Analysis | [email protected] |
| Mar 11, 2025 | New CVE Received | [email protected] |