CVE-2025-54899
HIGHDescription
Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Is your site exposed to CVE-2025-54899?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| microsoft | 365_apps |
| microsoft | 365_apps |
| microsoft | excel |
| microsoft | excel |
| microsoft | office |
| microsoft | office |
| microsoft | office_long_term_servicing_channel |
| microsoft | office_long_term_servicing_channel |
| microsoft | office_long_term_servicing_channel |
| microsoft | office_long_term_servicing_channel |
| microsoft | office_long_term_servicing_channel |
| microsoft | office_long_term_servicing_channel |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-54899? +
How severe is CVE-2025-54899? +
What products are affected by CVE-2025-54899? +
How do I check if I'm vulnerable to CVE-2025-54899? +
Related Vulnerabilities
A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series …
Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to …
A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to …
SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory read access …
SAP MDM Server Read function allows an attacker to send specially crafted packets which could trigger a memory read access …
In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation …