CVE-2025-53733
8.4Microsoft · Office Word
An incorrect numeric type conversion vulnerability in Microsoft Office Word allows an unauthorized local attacker to execute arbitrary code.
Executive summary
A critical numeric conversion vulnerability in Microsoft Office Word enables unauthorized local code execution, posing a significant risk to system integrity.
Vulnerability
This flaw stems from an incorrect conversion between numeric types (CWE-681) within Microsoft Office Word. An unauthorized attacker capable of local access can leverage this defect to achieve arbitrary code execution on the target system.
Business impact
Successful exploitation allows an attacker to gain full control over the local system, leading to complete compromise of confidentiality, integrity, and availability. With a CVSS score of 8.4, this vulnerability represents a high-severity risk that could facilitate data theft, privilege escalation, or the deployment of persistent malware within the corporate environment.
Remediation
Immediate Action: Update all affected Microsoft Office installations to the versions specified in the official Microsoft Security Update Guide (https://aka.ms/OfficeSecurityReleases).
Proactive Monitoring: Monitor endpoint security logs for unauthorized file executions or suspicious parent-child process relationships originating from Microsoft Word.
Compensating Controls: Enforce strict application control policies and restrict the ability of unauthorized users to execute files in directories writable by non-privileged accounts.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS score and the potential for total system compromise, organizations should prioritize patching their Microsoft Office deployments. IT administrators must ensure that all relevant updates are tested and deployed across the enterprise to mitigate the risk of local code execution.
More Microsoft CVEs
Sources
- Microsoft Word Remote Code Execution Vulnerability Vendor advisory