Junglewise Threat Intelligence

CVE-2025-49702: Microsoft Office type confusion local code execution

CVE-2025-49702 · Severity: high · CVSS 7.8 · Published 2025-07-08

Technologies: Microsoft Office LTSC 2024, Microsoft Office for Android, Microsoft Office LTSC 2021, Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

Microsoft Office is a widely used suite of productivity applications including Word, Excel, and PowerPoint. A security flaw has been identified that could allow an attacker to run malicious code on a user's computer if the user is tricked into opening a specially crafted file. This could lead to a full system compromise, unauthorized data access, or the installation of malware.

Technical details

A type confusion vulnerability (CWE-843) exists in Microsoft Office across multiple platforms including Windows, macOS, and Android. The flaw occurs when the application accesses a resource using an incompatible type, which can be triggered by a local attacker. Exploitation requires user interaction, typically involving a victim opening a malicious file. Successful exploitation allows for arbitrary code execution in the context of the current user. Affected versions include Office 2016, 2019, LTSC 2021, LTSC 2024, and Microsoft 365 Apps.

Affected products

  • Microsoft Office 2016 x86, x64
  • Microsoft Office 2019 x86, x64
  • Microsoft Office LTSC 2021 x86, x64, macOS
  • Microsoft Office LTSC 2024 x86, x64, macOS
  • Microsoft 365 Apps for Enterprise x86, x64
  • Microsoft Office for Android
  • Microsoft 365 Copilot for Android

Timeline

  • 2025-07-08: advisory: Initial disclosure by Microsoft and NVD.

References

Related threats