CVE-2026-65657
365_apps: Use After Free (CVE-2026-65657)
Beschreibung
Metriken
Weakness-Klassen (CWE)
CWE-416Variant
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- Initial Analysis2026-08-14 15:31 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:* *cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:* *cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:* *cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:* *cpe:2.3:a:microsoft:microsoft_365:-:*:*:*:*:macos:*:* *cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:* *cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:* *cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:macos:-:* *cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:* *cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:* *cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:macos:-:*
- Reference Type: Microsoft Corporation: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65657 Types: Vendor Advisory
- CVE Modified2026-08-11 20:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-65657","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-08-11 17:18 UTC· secure@microsoft.com
- Affected: Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac (+4)
- Description: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVSS V3.1: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- CWE: CWE-416
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
microsoft
365_apps
microsoft
microsoft_365
microsoft
office_2019
microsoft
office_2021
microsoft
office_2024