PT-2025-28600 · Microsoft · Office Word+1

Published

2025-07-08

·

Updated

2025-09-03

·

CVE-2025-49703

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Office Microsoft Word Microsoft 365 Apps for Enterprise Microsoft Office Long Term Servicing Channel Microsoft SharePoint Server versions prior to the July 15, 2025 update
Description A use-after-free issue exists in Microsoft Office Word. This allows an unauthorized attacker to execute code locally. The vulnerability also allows remote attackers to execute arbitrary code and affect the system.
Recommendations Install the security update for Microsoft Office LTSC for Mac 2021 and 2024, available as of July 15, 2025. Ensure all other affected Microsoft products are updated to a version released on or after July 15, 2025.

Fix

RCE

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2025-08435
CVE-2025-49703

Affected Products

Office Word
Sharepoint Server