CVE-2025-54907

7.8

Microsoft · Office Visio

A heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute arbitrary code locally.

Executive summary

A critical heap-based buffer overflow in Microsoft Office Visio exposes users to potential arbitrary code execution via local attack vectors.

Vulnerability

This vulnerability is a heap-based buffer overflow (CWE-122) within the Visio application. The flaw can be triggered by an unauthorized attacker, though successful exploitation typically requires user interaction, such as opening a specially crafted file.

Business impact

The potential for arbitrary code execution poses a severe risk to organizational security, as it could allow an attacker to gain control over local systems. With a CVSS score of 7.8, this vulnerability is classified as High severity, indicating a significant threat to confidentiality, integrity, and availability. Compromised workstations may serve as a beachhead for further lateral movement within the corporate network.

Remediation

Immediate Action: Apply the latest security updates provided by Microsoft via the official update guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-54907.

Proactive Monitoring: Monitor endpoint logs for unusual child process creation spawned by Visio, which may indicate an attempt to execute malicious code.

Compensating Controls: Ensure that Microsoft Office macro security settings are configured to block untrusted content and utilize endpoint detection and response (EDR) tools to alert on anomalous memory access patterns.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the potential for complete system compromise, IT administrators must prioritize the deployment of the vendor-supplied patches to all affected versions of Office Visio. Organizations should verify that automated update mechanisms are functioning correctly and verify that all enterprise instances are brought to the patched versions as specified in the Microsoft security release.

More Microsoft CVEs

Sources