Home
Description
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
PUBLISHED Reserved 2025-07-09 | Published 2025-08-12 | Updated 2025-09-17 | Assigner microsoft
HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Problem types
CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')
Product status
1.0.0 before 16.0.10417.20034
affected
19.0.0 before https://aka.ms/OfficeSecurityReleases
affected
16.0.1 before https://aka.ms/OfficeSecurityReleases
affected
16.0.1 before 16.100.25081015
affected
16.0.1 before https://aka.ms/OfficeSecurityReleases
affected
1.0.0 before https://aka.ms/OfficeSecurityReleases
affected
1.0.0 before 16.100.25081015
affected
16.0.0.0 before 16.0.5513.1000
affected
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53739 (Microsoft Excel Remote Code Execution Vulnerability) vendor-advisory
cve.org
(CVE-2025-53739)
nvd.nist.gov
(CVE-2025-53739)
Download JSON