CVE-2025-49697 is a high-severity heap-based buffer overflow vulnerability in Microsoft Office, Microsoft 365 Apps, and related Office products. It carries a CVSS score of 8.4 (HIGH) due to its potential for local code execution with high impact on confidentiality, integrity, and availability, requiring no user interaction. While not currently listed in CISA KEV or having public exploit code, its high FAUCET Risk Score of 80/100, coupled with significant community discussion and media coverage, indicates a notable threat that warrants prompt patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:365_copilot:-:*:*:*:*:android:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:x64:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:x86:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.