CVE-2025-26642: Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Other sources
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5495.1000Patch KB5002701 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5495.1000Patch KB5002703 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.96.25041326 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5495.1000Patch KB5002704 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20003Patch KB5002691 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20003Patch KB5002699
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26642?
CVE-2025-26642 has been categorized as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2025-26642?
To fix CVE-2025-26642, ensure that your Microsoft Office product is updated to the latest security patch provided by Microsoft.
Which Microsoft Office versions are affected by CVE-2025-26642?
CVE-2025-26642 affects various versions of Microsoft Office, including Office LTSC for Mac 2024 and 2021, Excel 2016, and Office 2019.
What are the potential consequences of CVE-2025-26642 if exploited?
If exploited, CVE-2025-26642 may allow an unauthorized attacker to execute arbitrary code on the affected system, compromising its security.
Is there a workaround for CVE-2025-26642 before applying the patch?
Currently, there are no effective workarounds for CVE-2025-26642, so updating to the latest version is strongly recommended.