CVE-2025-54906: Microsoft Office Remote Code Execution Vulnerability
Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Office Remote Code Execution Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54906?
The CVE-2025-54906 vulnerability is classified as a remote code execution vulnerability with high severity.
How do I fix CVE-2025-54906?
To mitigate CVE-2025-54906, users should apply the latest security updates available for their affected Microsoft Office products.
Which versions of Microsoft Office are affected by CVE-2025-54906?
CVE-2025-54906 affects multiple versions of Microsoft Office, including Office LTSC 2024, Office 2016, Office 2019, and various SharePoint Server versions.
Can CVE-2025-54906 be exploited remotely?
Yes, CVE-2025-54906 can be exploited remotely by an unauthorized attacker to execute code locally.
What type of vulnerability is CVE-2025-54906?
CVE-2025-54906 is a remote code execution vulnerability that occurs due to improper memory handling in Microsoft Office.