CVE-2025-54902

7.8

Microsoft · Office Excel

An out-of-bounds read vulnerability in Microsoft Office Excel allows an unauthorized attacker to execute code locally through a specially crafted file.

Executive summary

A critical out-of-bounds read vulnerability in Microsoft Office Excel enables local code execution, posing a significant risk to system integrity and data confidentiality.

Vulnerability

This vulnerability involves out-of-bounds read and use-after-free flaws within Excel, which can be triggered by an unauthorized attacker. Successful exploitation requires user interaction, typically through opening a malicious file, to achieve local code execution.

Business impact

Successful exploitation of this vulnerability could lead to a full compromise of the affected system, including unauthorized data access and potential lateral movement within the network. With a CVSS score of 7.8, this flaw is categorized as High severity, reflecting the significant impact on system confidentiality, integrity, and availability.

Remediation

Immediate Action: Apply the latest security updates provided in the Microsoft Security Update Guide immediately to remediate the vulnerable code paths.

Proactive Monitoring: Monitor endpoint activity for suspicious file execution patterns or unexpected child processes spawned by Excel.exe.

Compensating Controls: Utilize endpoint protection software to scan incoming documents for malicious content and enforce policies that restrict macros or untrusted file execution.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit available.

Analyst recommendation

Given the severity of this vulnerability and the potential for total system compromise, administrators must prioritize the deployment of Microsoft security patches to all affected workstations and servers. Users should be advised to exercise caution when opening unexpected Excel files, and security teams should ensure that automated update mechanisms are functioning correctly to minimize the window of exposure.

More Microsoft CVEs

Sources