Executive brief
A vulnerability in Microsoft Office could allow an attacker to run unauthorized code on a user's computer. Microsoft Office is a widely used suite of productivity applications, and an exploit could lead to full system compromise, data theft, or the installation of malware. This issue affects various versions of Office across Windows, macOS, and Android platforms.
Technical details
This vulnerability is characterized as an out-of-bounds read (CWE-125) and a heap-based buffer overflow (CWE-122) within Microsoft Office. The flaw allows an unauthorized attacker to achieve local code execution on the affected system. While the attack vector is local, the CVSS metric indicates no prior privileges (PR:N) or user interaction (UI:N) are required once the attacker has local access or a means to deliver the exploit. The vulnerability impacts a broad range of products including Office 2016, 2019, LTSC 2021/2024, and Microsoft 365 Apps. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Office 2016 x86 and x64 editions
- Microsoft Office 2019 x86 and x64 editions
- Microsoft Office LTSC 2021 Windows and macOS editions
- Microsoft Office LTSC 2024 Windows and macOS editions
- Microsoft 365 Apps for Enterprise x86 and x64 editions
- Microsoft Office for Android
Timeline
- 2025-07-08: disclosed: Initial disclosure by Microsoft Corporation
- 2025-07-08: advisory: Microsoft Security Update Guide published