PT-2025-15576 · Microsoft · Office

0X140Ce

·

Published

2025-04-08

·

Updated

2025-04-15

·

CVE-2025-29791

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Office (affected versions not specified)
Description The issue is related to a 'type confusion' error in Microsoft Office, allowing an unauthorized attacker to execute code locally. This can enable remote attackers to execute arbitrary code and affect the system. The vulnerability is associated with errors in mixing data types in Microsoft Excel, part of the Microsoft Office and Microsoft 365 Apps for Enterprise packages.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-04055
CVE-2025-29791

Affected Products

Office