Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 16.0.1 (custom) before https://aka.ms/OfficeSecurityReleases
affected
16.0.0 (custom) before 16.0.5495.1002
affected
19.0.0 (custom) before https://aka.ms/OfficeSecurityReleases
affected
16.0.1 (custom) before https://aka.ms/OfficeSecurityReleases
affected
16.0.0 (custom) before https://aka.ms/OfficeSecurityReleases
affected
16.0.1 (custom) before 16.96.25041326
affected
16.0.0 (custom) before 16.96.25041326
affected
16.0.1 (custom) before 16.0.5495.1002
affected
Description
Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network.
Problem types
CWE-349: Acceptance of Extraneous Untrusted Data With Trusted Data
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29816 (Microsoft Word Security Feature Bypass Vulnerability)