Buffer Over-Read Vulnerability in Microsoft Office Excel
CVE-2025-54901

5.5MEDIUM

What is CVE-2025-54901?

A buffer over-read vulnerability in Microsoft Office Excel has been identified, allowing unauthorized attackers to potentially disclose sensitive information locally. This issue arises from improper handling of data, which can be exploited to leak confidential data. Users are advised to apply the latest patches and updates to mitigate this risk effectively.

Affected Version(s)

Microsoft 365 Apps for Enterprise 32-bit Systems 16.0.1

Microsoft Excel 2016 32-bit Systems 16.0.0.0 < 16.0.5517.1000

Microsoft Office 2019 32-bit Systems 19.0.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54901 : Buffer Over-Read Vulnerability in Microsoft Office Excel