CVE-2025-59229
published 2025-10-14CVE-2025-59229: Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally.
PriorityP423medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.39%
31.7th percentile
Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2024 | >= 16.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | office_long_term_servicing_channel | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_office_ltsc_2024_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2024_for_64-bit_editions | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Office Denial of Service Vulnerability
vendor_msrc·2025-10-14·CVSS 5.5
CVE-2025-59229 [MEDIUM] CWE-248 Microsoft Office Denial of Service Vulnerability
Microsoft Office Denial of Service Vulnerability
Description: Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker must send a user a malicious Office file and convince them to open it.
FAQ: Is the Preview Pane an attack vector for this vulnerability?
Yes, the Preview Pane is an attack vector.
Microsoft Office: Microsoft Office
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely
Remediation: Click to Run
Reference: https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-upda
GHSA
GHSA-pv25-8q8x-9236: Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally
ghsa_unreviewed·2025-10-14
CVE-2025-59229 [MEDIUM] CWE-248 GHSA-pv25-8q8x-9236: Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally
Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally.
No detection rules found.
No public exploits indexed.
2025-10-14
Published