CVE-2025-54899
published 2025-09-09CVE-2025-54899: Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
PriorityP345high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.54%
41.8th percentile
Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel | — | — |
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_excel_2016 | >= 16.0.0.0 < 16.0.5517.1000 | 16.0.5517.1000 |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2021 | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2024 | >= 16.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_for_mac_2021 | >= 16.0.1 < 16.101.25091314 | 16.101.25091314 |
| microsoft | microsoft_office_ltsc_for_mac_2024 | >= 16.0.0 < 16.101.25091314 | 16.101.25091314 |
| microsoft | office | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_excel_2016 | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2024_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2024_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_for_mac_2021 | — | — |
| msrc | microsoft_office_ltsc_for_mac_2024 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Excel Remote Code Execution Vulnerability
vendor_msrc·2025-09-09·CVSS 7.8
CVE-2025-54899 [HIGH] CWE-590 Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Description: Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker must send a user a malicious Office file and convince them to open it.
FAQ: Are the updates for the Microsoft Office LTSC for Mac currently available?
The security update for Microsoft Office LTSC for Mac 2021 and 2024 are not immediately available. The updates will be released as soon as possible, and when they are available, customers will be notified via a revision to this CVE information.
FAQ: Are the updates for Microsoft Office LTSC for Mac 2021 and 2024 currently available?
Yes
GHSA
GHSA-2648-39fc-pr84: Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally
ghsa_unreviewed·2025-09-09
CVE-2025-54899 [HIGH] CWE-590 GHSA-2648-39fc-pr84: Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally
Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
No detection rules found.
No public exploits indexed.
2025-09-09
Published