CVE-2025-53732

7.8

Microsoft · Office

A heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally via manipulated files.

Executive summary

A critical heap-based buffer overflow in Microsoft Office for Android and Universal platforms could allow an unauthorized attacker to execute arbitrary code on the host system.

Vulnerability

This vulnerability is a heap-based buffer overflow (CWE-122) triggered when the application processes a malformed file. The CVSS vector (AV:L/UI:R) indicates that successful exploitation requires local access and user interaction, such as opening a malicious document.

Business impact

Successful exploitation of this vulnerability permits an attacker to achieve local code execution with the privileges of the logged-in user. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to full system compromise, unauthorized data access, or the deployment of persistent malware within the enterprise environment.

Remediation

Immediate Action: Update Microsoft Office for Android and Universal installations to the versions specified in the Microsoft Security Update Guide (16.0.19127.20000 and 16.0.14326.22618 respectively).

Proactive Monitoring: Review application logs for abnormal crashes or unexpected process spawning associated with Office components.

Compensating Controls: Utilize endpoint protection software to scan incoming documents for malicious patterns and restrict the ability of Office applications to execute macros or external scripts from untrusted sources.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability necessitates a prompt response to prevent potential system compromise. IT administrators should prioritize the deployment of the vendor-supplied patches across all affected mobile and universal endpoints to eliminate the underlying heap-based memory corruption flaw.

More Microsoft CVEs

Sources