CVE-2025-54910: Microsoft Office Remote Code Execution Vulnerability
Published Sep 9, 2025
·Updated
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Office Remote Code Execution Vulnerability
— Microsoft
Affected Software
24 affected componentsFixes available
Microsoft Office 2016
Microsoft Office LTSC 2024 for 32-bit editions
Microsoft 365 Apps for Enterprise
Microsoft Office LTSC 2024 for 64-bit editions
Microsoft Office 2016
Microsoft Office LTSC 2021 for 32-bit editions
Microsoft Office 2019 for 32-bit editions
Microsoft Office 2019 for 64-bit editions
Microsoft 365 Apps for Enterprise
Microsoft Office LTSC 2021 for 64-bit editions
Microsoft 365 Apps
Microsoft 365 Apps
Microsoft Office=2016
Microsoft Office=2016
Microsoft Office=2019
Microsoft Office=2019
Microsoft Office Long Term Servicing Channel=2021
Microsoft Office Long Term Servicing Channel=2021
Microsoft Office Long Term Servicing Channel Macos=2021
Microsoft Office Long Term Servicing Channel=2024
Microsoft Office Long Term Servicing Channel=2024
Microsoft Office Long Term Servicing Channel Macos=2024
Microsoft Office LTSC for Mac 2024
Microsoft Office LTSC for Mac 2021
Event History
Dec 10, 2024
News Published
08:48 PM
Jul 8, 2025
News Published
11:01 PM
Sep 9, 2025
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Description
CVE Published
via MITRE·05:01 PM
Data Sourced
via MITRE·05:01 PM
DescriptionSeverity
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Sep 10, 2025
News Published
via The Register·03:31 AM
News Published
via The Register·03:36 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-54910?
CVE-2025-54910 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-54910?
To fix CVE-2025-54910, ensure that your Microsoft Office software is updated to the latest security patches and versions.
3
What types of Microsoft Office are affected by CVE-2025-54910?
CVE-2025-54910 affects multiple versions including Office 2016, 2019, LTSC 2021, LTSC 2024, and 365 Apps for Enterprise.
4
Can CVE-2025-54910 be exploited remotely?
Yes, CVE-2025-54910 allows an unauthorized attacker to execute code locally, which can lead to further attacks.
5
What are the potential impacts of CVE-2025-54910?
The potential impacts of CVE-2025-54910 include unauthorized access, data breaches, and loss of system integrity.