CVE-2026-45474
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS
8.4
High
EPSS
0.4%
p30
KEV
—
Exploit Today
9
0-100
Published: Jun 9, 2026 · Last modified: Jul 23, 2026 · CWE-416 · CWE-787
0.4%EPSS · 30 days0.4%
2026-08-202026-09-17
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-252807.8 HIG1.5%
——0Memory corruption when processing escape handling flow with insufficient user buffer sizes.1dCVE-2026-240747.8 HIG5.8%
——2Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.1dCVE-2026-240737.8 HIG5.8%
——2Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.1dCVE-2026-927867.8 HIG2.7%
——1LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to write out-of-bounds memory during SHAP prediction. Attackers can craft malicious model files with invalid node references that trigger out-of-bounds writes at attacker-chosen offsets in the leaf_depth_ buffer during feature contribution computation.2dCVE-2026-924743.3 LOW4.5%
——1A security flaw has been discovered in GPAC 26.08-DEV. This affects the function gf_inline_get_proto_lib of the file src/compositor/mpeg4_inline.c of the component Proto Link Handler. The manipulation results in use after free. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. Upgrading to version abi-16.24 mitigates this issue. The patch is identified as e34f4ba349d55cd1849f0bcf4cf46552732e2db7. Upgrading the affected component is recommended.2dCVE-2026-924733.3 LOW5.7%
——2A vulnerability was identified in GPAC 26.08-DEV. The impacted element is the function gf_sg_command_del of the file src/scenegraph/commands.c of the component BIFS Handler. The manipulation leads to use after free. The attack needs to be performed locally. The exploit is publicly available and might be used. Upgrading to version abi-16.24 is sufficient to resolve this issue. The identifier of the patch is e34f4ba349d55cd1849f0bcf4cf46552732e2db7. It is suggested to upgrade the affected component.2d