Executive brief
A vulnerability in Microsoft Office could allow an attacker to run unauthorized commands on a user's computer. Microsoft Office is a widely used suite of productivity applications including Word, Excel, and PowerPoint. If exploited, this flaw could allow an attacker to gain full control over the affected system, potentially leading to data theft or the installation of malicious software.
Technical details
A type confusion vulnerability (CWE-843) exists in Microsoft Office due to the application accessing resources using an incompatible type. The vulnerability can be exploited locally by an unauthorized attacker to execute arbitrary code with the privileges of the current user. While the attack vector is local, the Microsoft CVSS assessment indicates that no prior administrative privileges or user interaction are required for successful exploitation. Affected versions include various editions of Office 2016, 2019, LTSC 2021, LTSC 2024, Microsoft 365 Apps, and Office for Android. Users are advised to apply the security updates provided by Microsoft.
Affected products
- Microsoft Office 2016 x86 and x64 editions
- Microsoft Office 2019 x86 and x64 editions
- Microsoft Office LTSC 2021 Windows and macOS versions
- Microsoft Office LTSC 2024 Windows and macOS versions
- Microsoft Microsoft 365 Apps for Enterprise x86 and x64 editions
- Microsoft Office for Android All versions
Timeline
- 2025-12-09: disclosed: Initial disclosure by Microsoft
- 2025-12-09: advisory: NVD entry created