Description
Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to execute arbitrary code, bypass security restrictions, obtain sensitive information, gain privileges, spoof user interface.
Below is a complete list of vulnerabilities:
- A remote code execution vulnerability in Microsoft Office can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Microsoft Excel can be exploited remotely to execute arbitrary code.
- An information disclosure vulnerability in Microsoft Excel can be exploited remotely to obtain sensitive information.
- An information disclosure vulnerability in Windows Imaging Component can be exploited remotely to obtain sensitive information.
- An information disclosure vulnerability in Microsoft Word can be exploited remotely to obtain sensitive information.
- An elevation of privilege vulnerability in Microsoft AutoUpdate (MAU) can be exploited remotely to gain privileges.
- A remote code execution vulnerability in Microsoft Office Visio can be exploited remotely to execute arbitrary code.
- A spoofing vulnerability in Microsoft OfficePlus can be exploited remotely to spoof user interface.
- A remote code execution vulnerability in Microsoft PowerPoint can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Microsoft SharePoint can be exploited remotely to execute arbitrary code.
Original advisories
- CVE-2025-54900
- CVE-2025-54904
- CVE-2025-54896
- CVE-2025-54901
- CVE-2025-53799
- CVE-2025-54899
- CVE-2025-54902
- CVE-2025-54905
- CVE-2025-54910
- CVE-2025-55317
- CVE-2025-54903
- CVE-2025-54898
- CVE-2025-54907
- CVE-2025-55243
- CVE-2025-54908
- CVE-2025-54897
Related products
- Microsoft-Office-PowerPoint
- Microsoft-Office
- Microsoft-Excel
- Microsoft-Word
- Microsoft-Sharepoint-Server
- Microsoft-SharePoint
CVE list
- CVE-2025-53799 high
- CVE-2025-54896 critical
- CVE-2025-54897 critical
- CVE-2025-54898 critical
- CVE-2025-54899 critical
- CVE-2025-54900 critical
- CVE-2025-54901 high
- CVE-2025-54902 critical
- CVE-2025-54903 critical
- CVE-2025-54904 critical
- CVE-2025-54905 high
- CVE-2025-54906 critical
- CVE-2025-54907 critical
- CVE-2025-54908 critical
- CVE-2025-54910 critical
- CVE-2025-55243 critical
- CVE-2025-55317 critical
KB list
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!