CVE-2025-54902
published 2025-09-09CVE-2025-54902: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
PriorityP342high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.54%
41.8th percentile
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel | — | — |
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_excel_2016 | >= 16.0.0.0 < 16.0.5517.1000 | 16.0.5517.1000 |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2021 | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2024 | >= 16.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_for_mac_2021 | >= 16.0.1 < 16.101.25091314 | 16.101.25091314 |
| microsoft | microsoft_office_ltsc_for_mac_2024 | >= 16.0.0 < 16.101.25091314 | 16.101.25091314 |
| microsoft | office | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | office_online_server | < 16.0.10417.20047 | 16.0.10417.20047 |
| microsoft | office_online_server | >= 16.0.0.0 < 16.0.10417.20047 | 16.0.10417.20047 |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_excel_2016 | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2024_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2024_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_for_mac_2021 | — | — |
| msrc | microsoft_office_ltsc_for_mac_2024 | — | — |
| msrc | office_online_server | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Excel Remote Code Execution Vulnerability
vendor_msrc·2025-09-09·CVSS 7.8
CVE-2025-54902 [HIGH] CWE-125 Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Description: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
FAQ: Are the updates for the Microsoft Office LTSC for Mac currently available?
The security update for Microsoft Office LTSC for Mac 2021 and 2024 are not immediately available. The updates will be released as soon as possible, and when they are available, customers will be notified via a revision to this CVE information.
FAQ: Are the updates for Microsoft Office LTSC for Mac 2021 and 2024 currently available?
Yes. As of September 15, 2025, the security update for Microsoft Office LTSC for Mac 2021 and 2024 are available. Customers running Microsoft Office LTSC for Mac 2021 and 2024 should ensure the update is installed t
GHSA
GHSA-q3gj-hcpw-3429: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally
ghsa_unreviewed·2025-09-09
CVE-2025-54902 [HIGH] CWE-125 GHSA-q3gj-hcpw-3429: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
No detection rules found.
No public exploits indexed.
2025-09-09
Published