Executive brief
A vulnerability in Microsoft Office could allow an attacker to run malicious code on a user's computer. Microsoft Office is a widely used suite of productivity applications including Word, Excel, and PowerPoint. If successfully exploited, this flaw could allow an attacker to gain full control over the affected system, potentially leading to the theft of sensitive data or the installation of malware.
Technical details
A heap-based buffer overflow (CWE-122) exists in multiple versions of Microsoft Office, including Office 2016, 2019, LTSC 2021/2024, and Microsoft 365 Apps. The vulnerability is triggered when the application improperly handles data in memory, allowing an attacker to overwrite adjacent memory locations. Although the attack vector is classified as local, a successful exploit allows for arbitrary code execution with the privileges of the logged-in user. The vulnerability affects various platforms including Windows, macOS, and Android. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Office 2016
- Microsoft Office 2019
- Microsoft Office LTSC 2021
- Microsoft Office LTSC 2024
- Microsoft 365 Apps for Enterprise
- Microsoft Office Online Server up to (excluding) 16.0.10417.20027
- Microsoft Office for Android
Timeline
- 2025-07-08: disclosed: Initial disclosure by Microsoft
- 2025-07-08: advisory: Microsoft MSRC advisory published