Security readout for executives and security teams
Plain-English summary
A memory-management flaw in Microsoft Office could let an unauthorized attacker run code on an affected device. Successful exploitation could expose data, alter files, or disrupt operations. The supplied CVSS score is 8.4, making this a high-severity issue.
Executive priority
Treat as a high-priority endpoint remediation issue. Establish affected-device counts, prioritize sensitive and critical systems, and require evidence of update completion. Emergency response escalation is not supported solely by the supplied evidence because active exploitation is unconfirmed.
Technical view
CVE-2026-45472 is a use-after-free vulnerability, classified as CWE-416. The supplied vector describes local access, low complexity, no privileges, no user interaction, unchanged scope, and high confidentiality, integrity, and availability impacts. The source bundle does not describe the triggering component or attack path.
Likely exposure
Exposure applies to the listed Microsoft 365 Apps, Office 2016, Office 2019, Office LTSC 2021/2024, and specified Mac and Android editions. The supplied version entries are limited and should be reconciled with Microsoft's advisory before declaring systems affected or safe.
Exploitation context
The supplied sources do not establish active exploitation, and this CVE is not identified as CISA KEV. The CVSS vector indicates local attack access without privileges or user interaction, but the bundle does not explain how an attacker obtains local access or triggers the flaw.
Researcher notes
Important technical details remain unavailable in the bundle, including the affected Office component, object lifetime error, trigger conditions, corrected build numbers, and detection indicators. Avoid inferring email, document-opening, or remote-delivery vectors from the title alone; the supplied CVSS vector specifically reports local attack access.
Mitigation direction
Review Microsoft's CVE advisory for applicable security updates and corrected builds.
Prioritize updates on endpoints handling sensitive data or supporting critical operations.
Use normal change controls, then deploy Microsoft's applicable updates promptly.
Restrict local access to affected systems until remediation is confirmed.
Validation and detection
Inventory installed Office products, editions, platforms, and exact build numbers.
Compare each build with the applicability and remediation information in Microsoft's advisory.
Confirm applicable Microsoft updates installed successfully across managed endpoints.
Re-scan endpoints and investigate systems that remain outdated or cannot report status.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-416: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
2Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-416 · source CWE mapping
Use After Free
Use After Free represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.