CVE-2025-49696: Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Other sources
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49696?
CVE-2025-49696 is classified as a Remote Code Execution vulnerability, which can have a critical impact on affected systems.
How do I fix CVE-2025-49696?
To fix CVE-2025-49696, install the latest security updates provided by Microsoft for affected versions of Microsoft Office.
Which versions of Microsoft Office are affected by CVE-2025-49696?
CVE-2025-49696 affects several versions, including Microsoft Office LTSC 2021, Office 2016, Office 2019, Office 2024, and Microsoft 365 Apps for Enterprise.
Can CVE-2025-49696 be exploited remotely?
CVE-2025-49696 requires local access to the vulnerable system, making it a local exploit rather than a remote one.
What are the consequences of not addressing CVE-2025-49696?
Failure to address CVE-2025-49696 can lead to unauthorized code execution, potentially compromising the system’s integrity and data security.