CVE-2025-49703: Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
Other sources
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49703?
CVE-2025-49703 is classified as a critical vulnerability due to its ability to allow unauthorized remote code execution in Microsoft Office Word.
How do I fix CVE-2025-49703?
To mitigate CVE-2025-49703, ensure that your Microsoft Office applications are updated with the latest security patches from Microsoft.
Which versions of Microsoft Office are affected by CVE-2025-49703?
CVE-2025-49703 affects multiple versions of Microsoft Office including Office LTSC 2021, Office LTSC 2024, and Word 2016 for both 32-bit and 64-bit editions.
What types of attacks can exploit CVE-2025-49703?
CVE-2025-49703 can be exploited to execute arbitrary code, which may lead to data compromise or system control.
Is there a specific user scenario that triggers CVE-2025-49703?
CVE-2025-49703 can be triggered when a user opens or interacts with a specially crafted document in Microsoft Word.