CVE-2025-49697: Microsoft Office Remote Code Execution Vulnerability
Published Jul 8, 2025
·Updated
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Office Remote Code Execution Vulnerability
— Microsoft
Affected Software
28 affected componentsFixes available
Microsoft Office LTSC 2024 for 64-bit editions
Microsoft Office LTSC 2024 for 32-bit editions
Microsoft Office for Android
Microsoft Office LTSC 2021 for 32-bit editions
Microsoft Office LTSC 2021 for 64-bit editions
Microsoft 365 Apps for Enterprise
Microsoft Office LTSC for Mac 2021
Microsoft 365 Apps for Enterprise
Microsoft Office 2019 for 64-bit editions
Microsoft Office 2016
Microsoft Office 2019 for 32-bit editions
Microsoft Office 2016
Microsoft Office LTSC for Mac 2024
Microsoft Office Online Server
Microsoft 365 Apps
Microsoft 365 Apps
Microsoft 365 Copilot Android
Microsoft Office=2016
Microsoft Office=2016
Microsoft Office=2019
Microsoft Office=2019
Microsoft Office Long Term Servicing Channel=2021
Microsoft Office Long Term Servicing Channel=2021
Microsoft Office Long Term Servicing Channel Macos=2021
Microsoft Office Long Term Servicing Channel=2024
Microsoft Office Long Term Servicing Channel=2024
Microsoft Office Long Term Servicing Channel Macos=2024
Microsoft Office Online Server<16.0.10417.20027
Event History
Jul 8, 2025
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Description
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·04:58 PM
Data Sourced
via MITRE·04:58 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-49697?
CVE-2025-49697 has a critical severity rating due to the potential for arbitrary code execution.
2
How do I fix CVE-2025-49697?
To fix CVE-2025-49697, ensure that you update your Microsoft Office to the latest version provided by Microsoft.
3
Which versions of Microsoft Office are affected by CVE-2025-49697?
CVE-2025-49697 affects various versions including Office LTSC 2024, Office 2019, Office 2016, and others.
4
What type of vulnerability is CVE-2025-49697?
CVE-2025-49697 is classified as a heap-based buffer overflow vulnerability.
5
Can CVE-2025-49697 be exploited remotely?
Yes, CVE-2025-49697 can be exploited locally by an unauthorized attacker to execute code.