CVE-2025-49699: Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Other sources
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49699?
CVE-2025-49699 is classified as a critical remote code execution vulnerability due to the potential for an attacker to execute arbitrary code locally.
How do I fix CVE-2025-49699?
To fix CVE-2025-49699, apply the latest security updates provided by Microsoft for the affected versions of Microsoft Office.
Which Microsoft Office versions are impacted by CVE-2025-49699?
CVE-2025-49699 affects various versions, including Microsoft Office 2019, Office LTSC 2021, Outlook 2016, Word 2016, PowerPoint 2016, and Microsoft 365 Apps for Enterprise.
What causes the vulnerability CVE-2025-49699?
CVE-2025-49699 is caused by a use-after-free error in Microsoft Office, which can be exploited to allow an unauthorized attacker to execute code locally.
Is there a workaround for CVE-2025-49699?
Currently, the best approach to mitigate CVE-2025-49699 is to update to the latest version of Microsoft Office as there are no effective workarounds available.