CVE-2025-54896
📛 CVE Title
Microsoft Excel Remote Code Execution Vulnerability
Description
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- microsoft
- CVSS severity
- HIGH
- CVSS score
- 7.8 / 10
- CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C- Effective score
- 7.8 / 10 HIGH source: CNA overview
- MSRC score
- 7.8 / 10 HIGH MS rating: Important · Remote Code Execution
- CWE(s)
-
CWE-416 - Reserved
- 2025-07-31
- Published
- 2025-09-09 00:00 UTC
- Last updated
- 2025-09-16 00:00 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/54xxx/CVE-2025-54896.json
- Linked Threat
- CVE-2025-54896 — Microsoft Excel Remote Code Execution Vulnerability
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2025-09-09 17:16:00 UTC
- NVD last modified
- 2026-06-17 09:40:53 UTC
- NVD CVSS v3.1
- 7.8 / 10 HIGH source: secure@microsoft.com
- NVD CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H- Exploitability subscore
- 1.8 / 10
- Impact subscore
- 5.9 / 10
- EPSS score
- 0.0054 (probability of exploitation in next 30 days)
- EPSS percentile
- 42.42% vs all CVEs — higher = more likely to be exploited, as of 2026-08-06
NVD / KEV / EPSS data refreshed 2026-08-06 23:04 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2025-27359 - Assigner
- microsoft
- Published
- Sep 9, 2025, 5:00:53 PM
- Updated
- Feb 26, 2026, 5:49:00 PM
- EUVD base score (CVSS 3.1)
-
7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C - EUVD-reported EPSS
- 0.1300
- Vendors
- Microsoft
- Products
-
Microsoft Office LTSC for Mac 2021 (16.0.1 <16.101.25091314)Microsoft Office LTSC 2024 (16.0.0 <https://aka.ms/OfficeSecurityReleases)Microsoft Office LTSC 2021 (16.0.1 <https://aka.ms/OfficeSecurityReleases)Microsoft Office LTSC for Mac 2021 (N/A)Microsoft Office LTSC for Mac 2024 (N/A)Microsoft 365 Apps for Enterprise (16.0.1 <https://aka.ms/OfficeSecurityReleases)Microsoft Office LTSC for Mac 2024 (16.0.0 <16.101.25091314)Microsoft Excel 2016 (16.0.0.0 <16.0.5517.1000)Office Online Server (16.0.0.0 <16.0.10417.20047)Microsoft Office 2019 (19.0.0 <https://aka.ms/OfficeSecurityReleases)
- Aliases
-
GHSA-mx6f-w8rx-j88j
ENISA description: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EUVD references (1)
Microsoft Security Response Center MSRC
Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-09-24 03:03 UTC (source: CVRF).
- MS severity
- Important
- Impact
- Remote Code Execution
- MS CVSS base score
- 7.8 / 10 (temporal 6.8)
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C - Exploit assessment
- Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely
- Release
- 2025-Sep
Microsoft remediations / KB articles (7)
- 5002776 — Vendor Fix / Security Update (fixed build 16.0.10417.20047)
- https://support.microsoft.com/help/5002776 — None Available / 5002776
- Click to Run — Vendor Fix / Security Update (fixed build https://aka.ms/OfficeSecurityReleases)
- https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates — None Available / Click to Run
- Release Notes — Vendor Fix / Security Update (fixed build 16.101.25091314)
- 5002782 — Vendor Fix / Security Update (fixed build 16.0.5517.1000)
- https://support.microsoft.com/help/5002782 — None Available / 5002782
Microsoft FAQ (6)
According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to execute code from the local machine to exploit the vulnerability.
How could an attacker exploit the vulnerability?
An attacker who successfully exploits this vulnerability could achieve remote code execution without user interaction.
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
A user needs to be tricked into running malicious files.
Are the updates for Microsoft Office LTSC for Mac 2021 and 2024 currently available?
Yes. As of September 15, 2025, the security update for Microsoft Office LTSC for Mac 2021 and 2024 are available. Customers running Microsoft Office LTSC for Mac 2021 and 2024 should ensure the update is installed to be protected from this vulnerability.
Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
Are the updates for the Microsoft Office LTSC for Mac currently available?
The security update for Microsoft Office LTSC for Mac 2021 and 2024 are not immediately available. The updates will be released as soon as possible, and when they are available, customers will be notified via a revision to this CVE information.
Affected products (8)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Microsoft | Microsoft 365 Apps for Enterprise |
16.0.1 (affected)
|
32-bit Systems, x64-based Systems |
| Microsoft | Microsoft Excel 2016 |
16.0.0.0 (affected)
|
32-bit Systems, x64-based Systems |
| Microsoft | Microsoft Office 2019 |
19.0.0 (affected)
|
32-bit Systems, x64-based Systems |
| Microsoft | Microsoft Office LTSC 2021 |
16.0.1 (affected)
|
32-bit Systems, x64-based Systems |
| Microsoft | Microsoft Office LTSC 2024 |
16.0.0 (affected)
|
32-bit Systems, x64-based Systems |
| Microsoft | Microsoft Office LTSC for Mac 2021 |
16.0.1 (affected)
|
— |
| Microsoft | Microsoft Office LTSC for Mac 2024 |
16.0.0 (affected)
|
— |
| Microsoft | Office Online Server |
16.0.0.0 (affected)
|
— |
Affected products — CPE 2.3 (13) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:x64:*cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:x86:*cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:x64:*cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:x86:*cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x64:*cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x86:*cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:macos:*:*cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x64:*cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x86:*cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:macos:*:*cpe:2.3:a:microsoft:office_online_server:*:*:*:*:*:*:*:*
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- Microsoft Excel Remote Code Execution Vulnerability vendor-advisorypatch
Web references (10)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- None Available msrc
- Release Notes msrc
- MSRC update guide: CVE-2025-54896 msrc
- 5002782 msrc
- 5002776 msrc
- https://support.microsoft.com/help/5002776 rapid7:support.microsoft.com
- https://attackerkb.com/topics/CVE-2025-54896 rapid7:attackerkb.com
- http://cwe.mitre.org/data/definitions/416.html rapid7:cwe.mitre.org
- https://support.microsoft.com/help/5002782 rapid7:support.microsoft.com
- https://www.cve.org/CVERecord?id=CVE-2025-54896 rapid7:www.cve.org
NVD-tagged references (1)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-54896 secure@microsoft.com Vendor Advisory
Remediations (18)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:www.microsoft.com
These Knowledge Base articles accompany all security updates and advisories, and include caveats or known issues with security updates. Additionally, support engineers document common concerns from customers in these KB articles. These Knowledge Base articles are published the Security Update Guide with each release on Patch Tuesday.
2026-09-24 06:26 UTC -
web:www.microsoft.com
Help protect your computing environment by keeping up to date on Microsoft technical security notifications. Security Update Guide Notifications Microsoft's free Security Update Guide Notifications provide links to security-related software updates and notification of re-released security updates. These notifications are sent via email throughout the month as needed. You can choose the type of ...
2026-09-24 06:26 UTC -
web:learn.microsoft.com
As of November 11, 2025 , Home and Pro editions of Windows 11, version 23H2 have reached end of servicing. Enterprise and Education editions of version 23H2 will continue to receive monthly security updates until November 10, 2026.
2026-09-24 06:26 UTC -
web:senserva.com
Every Microsoft security patch (KB) and the CVEs it fixes, with severity, CVSS, and CISA KEV status. Cross-linked to the CVE reference.
2026-09-24 06:26 UTC -
web:support.microsoft.com
Be aware that the update in the Microsoft Download Center applies to the Microsoft Installer (.msi)-based edition of Office 2016. It doesn't apply to the Office 2016 Click-to-Run editions, such as Microsoft Office 365 Home. (See What version of Office am I using?) How to get and install the update Method 1: Microsoft Update This update is available from Microsoft Update. When you turn on ...
2026-09-24 06:26 UTC -
web:msrc.microsoft.com
Access Microsoft Security Response Center's guide to address vulnerabilities, manage security risks, and keep your systems protected with the latest updates.
2026-09-24 06:26 UTC -
web:portal.msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
2026-09-24 06:26 UTC -
web:github.com
CVEfixes: Automated Collection of Vulnerabilities and Their Fixes from Open-Source Software - secureIT-project/CVEfixes
2026-09-24 06:26 UTC -
web:www.techrepublic.com
Microsoft's April 2026 Patch Tuesday fixes 165 vulnerabilities, including two zero-days, in one of the company's largest monthly security updates.
2026-05-22 14:34 UTC -
web:www.virustotal.com
Streamline your investigations with Google Threat Intelligence Agentic and the new Dark Web (DDW) module. Perform hunting and pivoting across forums using natural language or specific modifiers. Bridge threat actor identities and map global operations easy.
2026-05-22 14:34 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's May 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-05-22 14:34 UTC -
web:it.lbl.gov
A new attack technique, dubbed "ClickFix," has emerged, putting computer users at risk of compromising their own devices. This attack begins with a deceptive message or warning that appears on your screen, claiming that your computer has a problem or needs to be fixed. The message then instructs you to " fix " the issue by copying and pasting code into your computer. However, this code ...
2026-05-22 14:34 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 14:34 UTC -
web:www.computerworld.com
Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...
2026-05-22 14:34 UTC -
web:www.esri.com
Key highlights The ArcGIS Server Security 2025 update 2 is available This patch resolves 10 Medium severity vulnerabilities This security patch is cumulative, and includes fixes provided in the ArcGIS Server Security 2025 update 1.
2026-05-22 14:34 UTC -
web:www.msn.com
Microsoft suggests the threat is being used in phishing attacks against vulnerable systems since successful exploitation requires local access to the PC.
2026-05-22 14:34 UTC -
web:www.oracle.com
This Critical Patch Update contains 374 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at October 2025 Critical Patch Update: Executive Summary and Analysis.
2026-05-22 14:34 UTC -
web:www.securityweek.com
Microsoft has released patches for dozens of flaws in Windows and other products, including ones with a 'likely exploitation' rating.
2026-05-22 14:34 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2025-54896.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-54896",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-09-10T03:55:55.019486Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-02-26T17:49:00.615Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"platforms": [
"32-bit Systems",
"x64-based Systems"
],
"product": "Microsoft 365 Apps for Enterprise",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "https://aka.ms/OfficeSecurityReleases",
"status": "affected",
"version": "16.0.1",
"versionType": "custom"
}
]
},
{
"platforms": [
"32-bit Systems",
"x64-based Systems"
],
"product": "Microsoft Excel 2016",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "16.0.5517.1000",
"status": "affected",
"version": "16.0.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"32-bit Systems",
"x64-based Systems"
],
"product": "Microsoft Office 2019",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "https://aka.ms/OfficeSecurityReleases",
"status": "affected",
"version": "19.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"32-bit Systems",
"x64-based Systems"
],
"product": "Microsoft Office LTSC 2021",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "https://aka.ms/OfficeSecurityReleases",
"status": "affected",
"version": "16.0.1",
"versionType": "custom"
}
]
},
{
"platforms": [
"32-bit Systems",
"x64-based Systems"
],
"product": "Microsoft Office LTSC 2024",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "https://aka.ms/OfficeSecurityReleases",
"status": "affected",
"version": "16.0.0",
"versionType": "custom"
}
]
},
{
"product": "Microsoft Office LTSC for Mac 2021",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "16.101.25091314",
"status": "affected",
"version": "16.0.1",
"versionType": "custom"
}
]
},
{
"product": "Microsoft Office LTSC for Mac 2024",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "16.101.25091314",
"status": "affected",
"version": "16.0.0",
"versionType": "custom"
}
]
},
{
"product": "Office Online Server",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "16.0.10417.20047",
"status": "affected",
"version": "16.0.0.0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:office_2021:*:*:*:*:ltsc:*:*:*",
"versionEndExcluding": "16.0.10417.20047",
"versionStartIncluding": "16.0.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*",
"versionEndExcluding": "https://aka.ms/OfficeSecurityReleases",
"versionStartIncluding": "19.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*",
"versionEndExcluding": "https://aka.ms/OfficeSecurityReleases",
"versionStartIncluding": "16.0.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*",
"versionEndExcluding": "16.101.25091314",
"versionStartIncluding": "16.0.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*",
"versionEndExcluding": "https://aka.ms/OfficeSecurityReleases",
"versionStartIncluding": "16.0.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*",
"versionEndExcluding": "https://aka.ms/OfficeSecurityReleases",
"versionStartIncluding": "16.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*",
"versionEndExcluding": "16.101.25091314",
"versionStartIncluding": "16.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:excel_2016:*:*:*:*:*:*:x86:*",
"versionEndExcluding": "16.0.5517.1000",
"versionStartIncluding": "16.0.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"datePublic": "2025-09-09T07:00:00.000Z",
"descriptions": [
{
"lang": "en-US",
"value": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-416",
"description": "CWE-416: Use After Free",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-02-20T16:00:18.966Z",
"orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"shortName": "microsoft"
},
"references": [
{
"name": "Microsoft Excel Remote Code Execution Vulnerability",
"tags": [
"vendor-advisory",
"patch"
],
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-54896"
}
],
"title": "Microsoft Excel Remote Code Execution Vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"assignerShortName": "microsoft",
"cveId": "CVE-2025-54896",
"datePublished": "2025-09-09T17:00:53.019Z",
"dateReserved": "2025-07-31T18:54:19.611Z",
"dateUpdated": "2026-02-26T17:49:00.615Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}