CVE-2025-27748: Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Other sources
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5495.1002Patch KB5002623 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.96.25041326
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27748?
CVE-2025-27748 is classified as a critical vulnerability in Microsoft Office due to its potential for remote code execution.
How do I fix CVE-2025-27748?
To address CVE-2025-27748, you should apply the latest security updates provided by Microsoft for the affected Office products.
Which Microsoft products are affected by CVE-2025-27748?
CVE-2025-27748 affects various versions of Microsoft Office including Office 2016, Office 2019, Office LTSC 2021, and Microsoft 365 Apps for Enterprise.
Can CVE-2025-27748 allow remote attackers to access my system?
Yes, CVE-2025-27748 can allow unauthorized attackers to execute code locally on your system, making it a significant security risk.
Is there a known exploit for CVE-2025-27748?
As of now, specific exploit details for CVE-2025-27748 have not been publicly disclosed, but it is important to apply patches to mitigate risks.