CVE-2025-54899
CVE-2025-54899 is a high-severity vulnerability in Microsoft 365 Apps with a CVSS 3.x base score of 7.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-590.
Key facts
- Severity: High (CVSS 3.x base score 7.8)
- EPSS exploit prediction: 1% (46th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-27356
- Weakness: CWE-590
- Affected product: Microsoft 365 Apps
- Published:
- Last modified:
Description
Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Frequently asked questions
- What is CVE-2025-54899?
- Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- How severe is CVE-2025-54899?
- CVE-2025-54899 has a CVSS 3.x base score of 7.8, rated high severity. It is exploitable over local access with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2025-54899 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (46th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-54899?
- CVE-2025-54899 primarily affects Microsoft 365 Apps. In total, 12 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2025-54899?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- Does CVE-2025-54899 have an EU (EUVD) identifier?
- Yes. CVE-2025-54899 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-27356.
- When was CVE-2025-54899 published?
- CVE-2025-54899 was published on 2025-09-09 and last updated on 2026-06-17.
References
Affected products (12)
- cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
- cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
- cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:x64:*
- cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:x86:*
- cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:x64:*
- cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:x86:*
- cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x64:*
- cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x86:*
- cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:macos:*:*
- cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x64:*
- cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x86:*
- cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:macos:*:*
More vulnerabilities in Microsoft 365 Apps
- CVE-2026-78509 — Critical (CVSS 9.8): Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
- CVE-2024-21413 — Critical (CVSS 9.8): Microsoft Outlook Remote Code Execution Vulnerability
- CVE-2023-23397 — Critical (CVSS 9.8): Microsoft Outlook Elevation of Privilege Vulnerability
- CVE-2020-0901 — Critical (CVSS 9.8): A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle…
- CVE-2023-33150 — Critical (CVSS 9.6): Microsoft Office Security Feature Bypass Vulnerability
- CVE-2026-70125 — High (CVSS 8.8): Microsoft Office Outlook Remote Code Execution Vulnerability
All CVEs affecting Microsoft 365 Apps →
Other CWE-590 vulnerabilities
- CVE-2026-76465 — Critical (CVSS 9.8): A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco…
- CVE-2026-95311 — Critical (CVSS 9.6): Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social…
- CVE-2025-32911 — Critical (CVSS 9.0): A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition()…
- CVE-2026-20810 — High (CVSS 7.8): Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to…
- CVE-2025-42995 — High (CVSS 7.5): SAP MDM Server Read function allows an attacker to send specially crafted packets which could trigger a memory read…
- CVE-2025-42994 — High (CVSS 7.5): SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory…