CVE-2025-53732
7.8Microsoft · Office
A heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally via manipulated files.
Executive summary
A critical heap-based buffer overflow in Microsoft Office for Android and Universal platforms could allow an unauthorized attacker to execute arbitrary code on the host system.
Vulnerability
This vulnerability is a heap-based buffer overflow (CWE-122) triggered when the application processes a malformed file. The CVSS vector (AV:L/UI:R) indicates that successful exploitation requires local access and user interaction, such as opening a malicious document.
Business impact
Successful exploitation of this vulnerability permits an attacker to achieve local code execution with the privileges of the logged-in user. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to full system compromise, unauthorized data access, or the deployment of persistent malware within the enterprise environment.
Remediation
Immediate Action: Update Microsoft Office for Android and Universal installations to the versions specified in the Microsoft Security Update Guide (16.0.19127.20000 and 16.0.14326.22618 respectively).
Proactive Monitoring: Review application logs for abnormal crashes or unexpected process spawning associated with Office components.
Compensating Controls: Utilize endpoint protection software to scan incoming documents for malicious patterns and restrict the ability of Office applications to execute macros or external scripts from untrusted sources.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability necessitates a prompt response to prevent potential system compromise. IT administrators should prioritize the deployment of the vendor-supplied patches across all affected mobile and universal endpoints to eliminate the underlying heap-based memory corruption flaw.
More Microsoft CVEs
Sources
- Microsoft Office Remote Code Execution Vulnerability Vendor advisory