CVE-2025-29816: Microsoft Word Security Feature Bypass Vulnerability
Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network.
Other sources
Microsoft Word Security Feature Bypass Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5495.1002Patch KB5002702 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5495.1002Patch KB5002623 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.96.25041326
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29816?
CVE-2025-29816 is classified as a high severity vulnerability due to its potential to allow unauthorized access to bypass security features.
How do I fix CVE-2025-29816?
To fix CVE-2025-29816, ensure that you apply the latest security updates provided by Microsoft for the affected Office products.
Which Microsoft products are affected by CVE-2025-29816?
CVE-2025-29816 affects various Microsoft products including Microsoft 365 Apps for Enterprise, Office 2016, Office LTSC 2021, and Word 2016.
What kind of attacks can CVE-2025-29816 enable?
CVE-2025-29816 can enable attackers to bypass security features in Microsoft Office Word, potentially compromising sensitive data.
Is there a workaround for CVE-2025-29816 until a patch is applied?
Currently, no specific workaround is documented for CVE-2025-29816; applying the patch is the recommended approach.