PT-2025-6322 · Microsoft · Office+2

0X140Ce

·

Published

2025-02-11

·

Updated

2025-07-01

·

CVE-2025-21381

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Excel versions (affected versions not specified) Microsoft 365 Apps versions (affected versions not specified) Microsoft Office versions (affected versions not specified) Microsoft Office Online Server versions (affected versions not specified)
Description The issue allows remote attackers to execute arbitrary code and affect the system. It is related to the exploitation of a dangling pointer in Microsoft Office, Excel, and 365 Apps for Enterprise packages. This exploitation can enable an attacker to execute arbitrary code.
Recommendations For Microsoft Excel, update to a version that includes a fix for this issue. For Microsoft 365 Apps, apply configuration changes to restrict the exploitation of the vulnerable component until a patch is available. For Microsoft Office, consider disabling the vulnerable function temporarily to minimize the risk of exploitation. For Microsoft Office Online Server, restrict access to the vulnerable module to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Untrusted Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2025-01553
CVE-2025-21381

Affected Products

365 Apps For Enterprise
Office Excel
Office