CVE-2025-54902
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: secure@microsoft.com (Secondary)
Description
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Affected (13)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| Version 2016 | |
| Version 2019 | |
| Version 2021 | |
| Before 16.0.10417.20047 |
Related CWEs
CWE-125
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
CWE-416
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
References (1)
Source: secure@microsoft.com
Vendor Advisory
Timeline
No history available yet.