CVE-2025-27749: Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Other sources
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.96.25041326 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5495.1002Patch KB5002623
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27749?
CVE-2025-27749 has been classified with critical severity due to its potential for remote code execution.
How do I fix CVE-2025-27749?
To fix CVE-2025-27749, ensure that you update your affected Microsoft Office products to the latest version provided by Microsoft.
Which Microsoft Office products are affected by CVE-2025-27749?
CVE-2025-27749 affects multiple Microsoft Office products, including Office 2016, Office 2019, Office LTSC, and Microsoft 365 Apps for Enterprise.
What type of vulnerability is CVE-2025-27749?
CVE-2025-27749 is a use-after-free vulnerability that can allow unauthorized attackers to execute code locally.
Is there a workaround for CVE-2025-27749?
Currently, the best mitigation for CVE-2025-27749 is to apply the recommended security updates provided by Microsoft.