CVE-2025-32704: Microsoft Excel Remote Code Execution Vulnerability
Published May 13, 2025
·Updated
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Excel Remote Code Execution Vulnerability
— Microsoft
Affected Software
20 affected componentsFixes available
Microsoft Office LTSC 2021 for 32-bit editions
Microsoft 365 Apps for Enterprise
Microsoft Excel 2016
Microsoft Office LTSC 2021 for 64-bit editions
Microsoft Office LTSC 2024 for 64-bit editions
Microsoft Office 2019 for 32-bit editions
Microsoft Excel 2016
Microsoft Office 2019 for 64-bit editions
Microsoft Office LTSC 2024 for 32-bit editions
Microsoft 365 Apps for Enterprise
Microsoft 365 Apps
Microsoft 365 Apps
Microsoft Excel=2016
Microsoft Excel=2016
Microsoft Office=2019
Microsoft Office=2019
Microsoft Office Long Term Servicing Channel=2021
Microsoft Office Long Term Servicing Channel=2021
Microsoft Office Long Term Servicing Channel=2024
Microsoft Office Long Term Servicing Channel=2024
Event History
May 13, 2025
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
CVE Published
via MITRE·04:59 PM
Data Sourced
via MITRE·04:59 PM
DescriptionSeverity
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-32704?
CVE-2025-32704 has been classified with a high severity due to its potential for remote code execution.
2
How do I fix CVE-2025-32704?
To fix CVE-2025-32704, ensure that your Microsoft Office applications are updated to the latest security patches.
3
Which Microsoft products are affected by CVE-2025-32704?
CVE-2025-32704 affects various versions of Microsoft Office, including Office LTSC 2021, Office 2019, and Excel 2016.
4
Can CVE-2025-32704 be exploited without user interaction?
Yes, CVE-2025-32704 can be exploited by an attacker without requiring user interaction in certain contexts.
5
What types of attacks can CVE-2025-32704 enable?
CVE-2025-32704 enables an unauthorized attacker to execute code locally on the target system.