Description
Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to gain privileges, execute arbitrary code, bypass security restrictions, spoof user interface.
Below is a complete list of vulnerabilities:
- An elevation of privilege vulnerability in Microsoft AutoUpdate (MAU) can be exploited remotely to gain privileges.
- A remote code execution vulnerability in Microsoft SharePoint can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Microsoft Office can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Microsoft Excel can be exploited remotely to execute arbitrary code.
- An elevation of privilege vulnerability in Win32k can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Microsoft Office can be exploited remotely to gain privileges.
- A remote code execution vulnerability in Microsoft Word can be exploited remotely to execute arbitrary code.
- A security feature bypass vulnerability in Microsoft Word can be exploited remotely to bypass security restrictions.
- A security feature bypass vulnerability in Microsoft OneNote can be exploited remotely to bypass security restrictions.
Original advisories
- CVE-2025-29794
- CVE-2025-27745
- CVE-2025-29791
- CVE-2025-27750
- CVE-2025-27751
- CVE-2025-26642
- CVE-2025-26687
- CVE-2025-27748
- CVE-2025-27749
- CVE-2025-29792
- CVE-2025-27747
- CVE-2025-27746
- CVE-2025-29823
- CVE-2025-29816
- CVE-2025-27752
- CVE-2025-27744
- CVE-2025-29793
- CVE-2025-29800
- CVE-2025-29820
- CVE-2025-29822
Related products
CVE list
- CVE-2025-26642 critical
- CVE-2025-26687 critical
- CVE-2025-27744 critical
- CVE-2025-27745 critical
- CVE-2025-27746 critical
- CVE-2025-27747 critical
- CVE-2025-27748 critical
- CVE-2025-27749 critical
- CVE-2025-27750 critical
- CVE-2025-27751 critical
- CVE-2025-27752 critical
- CVE-2025-29791 critical
- CVE-2025-29792 high
- CVE-2025-29793 high
- CVE-2025-29794 critical
- CVE-2025-29800 critical
- CVE-2025-29801 critical
- CVE-2025-29816 critical
- CVE-2025-29820 critical
- CVE-2025-29822 critical
- CVE-2025-29823 critical
KB list
- 5002692
- 5002703
- 5002700
- 5002622
- 5002588
- 5002669
- 5002705
- 5002699
- 5002680
- 5002701
- 5002702
- 5002682
- 5002704
- 5002573
- 4484432
- 5002691
- 5002623
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!