Microsoft Office Type Confusion Vulnerability Leading to Remote Code Execution

Vulnerability

A type confusion vulnerability has been identified in Microsoft Office, allowing an unauthorized attacker to execute code locally. This issue arises from the access of a resource using an incompatible type. The vulnerability is present in several Microsoft Office applications, including Word, Excel, and Outlook, on Windows and Mac platforms. Exploitation requires user interaction, as an attacker must send a malicious file and convince the user to open it.

Impact

Exploitation of this vulnerability allows for remote code execution.

Reproduction

To reproduce this vulnerability, an attacker must send a malicious file to the user and convince them to open it. The Preview Pane can be used to trigger the vulnerability.

Remediation

Security updates are available for Microsoft Office LTSC for Mac 2021 and 2024. Customers should ensure these updates are installed. For Windows users, Microsoft released a security update (KB5002700) and a follow-up update (KB5002623) to address this vulnerability. Customers should install both updates.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
7.5
exploitability
4.8
remediation
7.7
relevance
0.0
threat
1.6
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.