880
VMScore

CVE-2025-26630

CVSSv4: NA | CVSSv3: 7.8 | CVSSv2: NA | VMScore: 880 | EPSS: 0.00085 | KEV: Not Included
Published: 11/03/2025 Updated: 11/03/2025

Vulnerability Summary

Use-After-Free Vulnerability in Microsoft Office Access Enables Local Code Execution

Use after free in Microsoft Office Access allows an unauthorized malicious user to execute code locally.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft microsoft office 2019

microsoft microsoft 365 apps for enterprise

microsoft microsoft office ltsc 2021

microsoft microsoft office ltsc 2024

microsoft microsoft access 2016 (32-bit edition)

microsoft microsoft access 2016

microsoft office 2019

microsoft 365 apps

microsoft office 2021

microsoft office 2024

microsoft access 2016

Recent Articles

Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws
BleepingComputer • Lawrence Abrams • 11 Mar 2025

Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws By Lawrence Abrams March 11, 2025 01:45 PM 2 .crit { font-weight:bold; color:red; } .article_section td { font-size: 14px!important; } Today is Microsoft's March 2025 Patch Tuesday, which includes security updates for 57 flaws, including six actively exploited zero-day vulnerabilities. This Patch Tuesday also fixes six "Critical" vulnerabilities, all remote code execution vulnerabilities. The number of bugs in each vulnerability...

Choose your own Patch Tuesday adventure: Start with six zero-day fixes, or six critical flaws
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Microsoft tackles 50-plus security blunders, Adobe splats 3D bugs, and Apple deals with a doozy

Patch Tuesday Microsoft’s Patch Tuesday bundle has appeared, with a dirty dozen flaws competing for your urgent attention – six of them rated critical and another six already being exploited by criminals. Let’s start with the six already exploited vulnerabilities, three of which impact Windows NTFS. The first is CVE-2025-24993 - a heap-based buffer overflow in NTFS used by Windows Server 2008 and later systems, as well as Windows 10 and 11. The flaw makes remote code execution (RCE) a poss...