CVE-2025-48812: Microsoft Excel Information Disclosure Vulnerability
Published Jul 8, 2025
·Updated
Microsoft Excel Information Disclosure Vulnerability
Other sources
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
— NVD
Affected Software
26 affected componentsFixes available
Microsoft Excel 2016
Microsoft Office LTSC 2024 for 64-bit editions
Microsoft Excel 2016
Microsoft Office LTSC 2021 for 64-bit editions
Microsoft Office LTSC 2024 for 32-bit editions
Microsoft Office 2019 for 32-bit editions
Microsoft Office Online Server
Microsoft 365 Apps for Enterprise
Microsoft Office LTSC 2021 for 32-bit editions
Microsoft 365 Apps for Enterprise
Microsoft Office 2019 for 64-bit editions
Microsoft 365 Apps
Microsoft 365 Apps
Microsoft Excel=2016
Microsoft Excel=2016
Microsoft Office=2019
Microsoft Office=2019
Microsoft Office Long Term Servicing Channel=2021
Microsoft Office Long Term Servicing Channel=2021
Microsoft Office Long Term Servicing Channel Macos=2021
Microsoft Office Long Term Servicing Channel=2024
Microsoft Office Long Term Servicing Channel=2024
Microsoft Office Long Term Servicing Channel Macos=2024
Microsoft Office Online Server<16.0.10417.20027
Microsoft Office LTSC for Mac 2024
Microsoft Office LTSC for Mac 2021
Event History
Jul 8, 2025
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Description
CVE Published
via MITRE·04:57 PM
Data Sourced
via MITRE·04:57 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48812?
The severity of CVE-2025-48812 is rated as high due to the potential for information disclosure.
2
How do I fix CVE-2025-48812?
To fix CVE-2025-48812, apply the latest security updates and patches provided by Microsoft for the affected versions of Excel.
3
What versions of Microsoft Excel are affected by CVE-2025-48812?
CVE-2025-48812 affects various versions of Excel, including Excel 2016, Office LTSC 2024, and Office 2019.
4
What type of vulnerability is CVE-2025-48812?
CVE-2025-48812 is classified as an out-of-bounds read vulnerability that allows unauthorized information disclosure.
5
Can CVE-2025-48812 be exploited remotely?
CVE-2025-48812 requires local access to the affected system for exploitation, so it cannot be exploited remotely.