CVE-2025-26642

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:access:2016:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office:2016:*:*:*:-:*:x64:*
cpe:2.3:a:microsoft:office:2016:*:*:*:-:*:x86:*
cpe:2.3:a:microsoft:office:2019:*:*:*:*:-:x64:*
cpe:2.3:a:microsoft:office:2019:*:*:*:*:-:x86:*
cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x64:*
cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x86:*
cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x64:*
cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x86:*
cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_online_server:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

History

09 Jul 2025, 16:56

Type Values Removed Values Added
First Time Microsoft 365 Apps
Microsoft access
Microsoft office Online Server
Microsoft
Microsoft office Long Term Servicing Channel
Microsoft sharepoint Server
Microsoft excel
Microsoft office
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26642 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26642 - Vendor Advisory
CPE cpe:2.3:a:microsoft:office_online_server:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:access:2016:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:2019:*:*:*:*:-:x86:*
cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x64:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:2016:*:*:*:-:*:x86:*
cpe:2.3:a:microsoft:office:2016:*:*:*:-:*:x64:*
cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x86:*
cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x86:*
cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office:2019:*:*:*:*:-:x64:*

09 Apr 2025, 20:03

Type Values Removed Values Added
Summary
  • (es) La lectura fuera de los límites en Microsoft Office permite que un atacante no autorizado ejecute código localmente.

08 Apr 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-08 18:15

Updated : 2025-07-09 16:56


NVD link : CVE-2025-26642

Mitre link : CVE-2025-26642

CVE.ORG link : CVE-2025-26642


JSON object : View

Products Affected

microsoft

  • sharepoint_server
  • excel
  • office_long_term_servicing_channel
  • 365_apps
  • office
  • access
  • office_online_server
CWE
CWE-125

Out-of-bounds Read

CWE-190

Integer Overflow or Wraparound