CVE-2025-29791: Microsoft Excel Remote Code Execution Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Excel Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5495.1002Patch KB5002623 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.96.25041326
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29791?
CVE-2025-29791 is considered a critical vulnerability as it allows unauthorized local code execution.
How do I fix CVE-2025-29791?
To fix CVE-2025-29791, update your affected Microsoft Office software to the latest version provided by Microsoft.
Which versions of Microsoft Office are affected by CVE-2025-29791?
CVE-2025-29791 affects multiple versions including Microsoft Office 2016, 2019, 2021, and 365 Apps for Enterprise.
What type of vulnerability is CVE-2025-29791?
CVE-2025-29791 is a type confusion vulnerability that can lead to resource access violations in Microsoft Office.
Can CVE-2025-29791 be exploited remotely?
CVE-2025-29791 requires local access, meaning it cannot be exploited remotely without user interaction.