CVE-2025-54901: Microsoft Excel Information Disclosure Vulnerability
Published Sep 9, 2025
·Updated
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Other sources
Microsoft Excel Information Disclosure Vulnerability
— Microsoft
Affected Software
24 affected componentsFixes available
Microsoft Excel 2016
Microsoft Excel 2016
Microsoft Office LTSC 2024 for 64-bit editions
Microsoft Office LTSC 2024 for 32-bit editions
Microsoft Office LTSC 2021 for 32-bit editions
Microsoft 365 Apps for Enterprise
Microsoft Office LTSC 2021 for 64-bit editions
Microsoft 365 Apps for Enterprise
Microsoft Office 2019 for 32-bit editions
Microsoft Office 2019 for 64-bit editions
Microsoft Office LTSC for Mac 2021
Microsoft Office LTSC for Mac 2024
Microsoft 365 Apps
Microsoft 365 Apps
Microsoft Excel=2016
Microsoft Excel=2016
Microsoft Office=2019
Microsoft Office=2019
Microsoft Office Long Term Servicing Channel=2021
Microsoft Office Long Term Servicing Channel=2021
Microsoft Office Long Term Servicing Channel Macos=2021
Microsoft Office Long Term Servicing Channel=2024
Microsoft Office Long Term Servicing Channel=2024
Microsoft Office Long Term Servicing Channel Macos=2024
Event History
Sep 9, 2025
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Description
CVE Published
via MITRE·05:01 PM
Data Sourced
via MITRE·05:01 PM
DescriptionSeverity
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-54901?
CVE-2025-54901 has been rated with a moderate severity level due to its potential for information disclosure.
2
How do I fix CVE-2025-54901?
To fix CVE-2025-54901, apply the latest security updates provided by Microsoft for your affected version of Excel.
3
Which software versions are affected by CVE-2025-54901?
CVE-2025-54901 affects multiple versions of Microsoft Excel, including Excel 2016, Office LTSC 2021 & 2024, and Office 2019.
4
Can CVE-2025-54901 be exploited remotely?
CVE-2025-54901 is not classified as a remote code execution issue and requires local access to exploit vulnerabilities.
5
What type of vulnerability is CVE-2025-54901?
CVE-2025-54901 is classified as a buffer over-read vulnerability leading to information disclosure.