First published: Tue Apr 08 2025(Updated: )
<p>Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.</p>
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office 2019 for Mac | ||
Microsoft 365 Apps for enterprise | ||
Microsoft Office Professional Plus 2016 | ||
Microsoft 365 Apps for enterprise | ||
Microsoft SharePoint Server Subscription Edition Language Pack | ||
Microsoft Office LTSC 2021 | ||
Microsoft Office Online Server | ||
Microsoft Office Professional Plus 2016 | ||
Microsoft Office LTSC 2021 | ||
Microsoft Office 2019 for Mac | ||
Microsoft Office LTSC 2024 | ||
Microsoft Office LTSC 2024 | ||
Microsoft Office Long Term Servicing Channel for Mac | ||
Microsoft Office Long Term Servicing Channel for Mac |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27746 is classified as a critical remote code execution vulnerability in Microsoft Office.
To fix CVE-2025-27746, users should apply the latest security updates provided by Microsoft for their Office version.
CVE-2025-27746 affects various versions of Microsoft Office including Office 2019, Office 2016, Microsoft 365 Apps, and Office LTSC.
CVE-2025-27746 requires local access to exploit, making it a local execution vulnerability.
CVE-2025-27746 can facilitate unauthorized code execution on the affected system.