Junglewise Threat Intelligence

CVE-2025-49697: Microsoft Office heap overflow code execution

CVE-2025-49697 · Severity: high · CVSS 8.4 · Published 2025-07-08

Technologies: Microsoft Office LTSC 2024, Microsoft Office for Android, Microsoft Office Online Server, Microsoft Office LTSC 2021, Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A vulnerability in Microsoft Office could allow an attacker to run malicious code on a user's computer. Microsoft Office is a widely used suite of productivity applications including Word, Excel, and PowerPoint. If successfully exploited, this flaw could allow an attacker to gain full control over the affected system, potentially leading to the theft of sensitive data or the installation of malware.

Technical details

A heap-based buffer overflow (CWE-122) exists in multiple versions of Microsoft Office, including Office 2016, 2019, LTSC 2021/2024, and Microsoft 365 Apps. The vulnerability is triggered when the application improperly handles data in memory, allowing an attacker to overwrite adjacent memory locations. Although the attack vector is classified as local, a successful exploit allows for arbitrary code execution with the privileges of the logged-in user. The vulnerability affects various platforms including Windows, macOS, and Android. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Office 2016
  • Microsoft Office 2019
  • Microsoft Office LTSC 2021
  • Microsoft Office LTSC 2024
  • Microsoft 365 Apps for Enterprise
  • Microsoft Office Online Server up to (excluding) 16.0.10417.20027
  • Microsoft Office for Android

Timeline

  • 2025-07-08: disclosed: Initial disclosure by Microsoft
  • 2025-07-08: advisory: Microsoft MSRC advisory published

References

Related threats