Executive brief
A vulnerability in Microsoft Office could allow an attacker to execute malicious code on a user's device. This issue affects various versions of Office across Windows, macOS, and Android, potentially leading to full system compromise or unauthorized data access. To exploit this, an attacker would typically need to have a presence on the local system or trick a user into running a malicious file.
Technical details
A type confusion vulnerability (CWE-843) exists in Microsoft Office due to the application accessing resources using an incompatible type. This flaw allows an attacker to bypass memory safety protections and execute arbitrary code in the context of the current user. The attack vector is local, meaning the attacker must already have a foothold on the system or deliver a malicious payload that is executed locally. The vulnerability impacts a wide range of products including Office 2016, 2019, LTSC versions, and Microsoft 365 Apps. Microsoft has released security updates to address this issue; users should update to the latest available versions, such as Android version 16.0.18925.20000 or later.
Affected products
- Microsoft Office 2016, 2019, LTSC 2021, LTSC 2024, 365 Apps for Enterprise, Android versions prior to 16.0.18925.20000
- Microsoft 365 Copilot Android versions prior to 16.0.18925.20000
Timeline
- 2025-06-10: disclosed
- 2025-06-10: advisory