CVE-2026-40418
published 2026-05-12CVE-2026-40418: Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
PriorityP345high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
16.9th percentile
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2021 | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2024 | >= 16.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | office | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-89vp-6c77-3jr6: Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally
ghsa_unreviewed·2026-05-12
CVE-2026-40418 [HIGH] CWE-416 GHSA-89vp-6c77-3jr6: Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally
Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
VulDB
Microsoft Office 365 Apps/2019/LTSC 2021/LTSC 2024 use after free
vuldb·2026-05-12
CVE-2026-40418 [CRITICAL] Microsoft Office 365 Apps/2019/LTSC 2021/LTSC 2024 use after free
A vulnerability, which was classified as critical, was found in Microsoft Office 2019/365 Apps/LTSC 2021/LTSC 2024. The affected element is an unknown function. The manipulation results in use after free.
This vulnerability is cataloged as CVE-2026-40418. The attack may be launched remotely. There is no exploit available.
It is advisable to implement a patch to correct this issue.
No detection rules found.
No public exploits indexed.
2026-05-12
Published