CVE-2025-54898

7.8

Microsoft · Office Excel

An out-of-bounds read vulnerability in Microsoft Office Excel allows a local attacker to execute arbitrary code.

Executive summary

A high-severity out-of-bounds read vulnerability in Microsoft Office Excel could allow a local attacker to execute arbitrary code on the host system.

Vulnerability

This flaw is an out-of-bounds read (CWE-125) occurring within Excel, which can be triggered by an attacker to facilitate local code execution. The vulnerability is categorized as requiring user interaction, though it allows for total technical impact upon successful exploitation.

Business impact

The vulnerability carries a CVSS score of 7.8, indicating a high risk to organizational security. Successful exploitation could lead to full system compromise, unauthorized data access, and the potential for lateral movement within the network, resulting in significant operational and reputational damage.

Remediation

Immediate Action: Apply the relevant security updates provided by Microsoft in the official update guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-54898.

Proactive Monitoring: Monitor system logs for unusual Excel process activity or unexpected crashes that may indicate exploitation attempts.

Compensating Controls: Ensure endpoint protection platforms are active and restrict the execution of untrusted Excel files from external or unverified sources.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the nature of the vulnerability, organizations should prioritize the deployment of the vendor-supplied patches across all affected versions of Microsoft Office. Timely remediation is the most effective method to prevent potential exploitation and ensure the integrity of the local environment.

More Microsoft CVEs

Sources