CVE-2025-49702: Microsoft Office Remote Code Execution Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Office Remote Code Execution Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49702?
CVE-2025-49702 has a high severity rating due to the potential for unauthorized code execution.
How do I fix CVE-2025-49702?
To fix CVE-2025-49702, update your Microsoft Office products to the latest version with the necessary security patches installed.
Which versions of Microsoft Office are affected by CVE-2025-49702?
CVE-2025-49702 affects multiple versions of Microsoft Office, including Office 2016, Office 2019, Office LTSC 2021, Office LTSC 2024, and Microsoft 365 Apps.
What type of vulnerability is CVE-2025-49702?
CVE-2025-49702 is a type confusion vulnerability that allows unauthorized attackers to execute code locally.
What impact does CVE-2025-49702 have on users?
Exploitation of CVE-2025-49702 could allow attackers to take control of affected systems and execute malicious code.