PatchSiren cyber security CVE debrief
CVE-2025-49696 Microsoft CVE debrief
CVE-2025-49696 is a Microsoft Office vulnerability described as an out-of-bounds read that may allow an unauthorized attacker to execute code locally. NVD assigns it CVSS 8.4 (HIGH) with local attack vector, no privileges required, no user interaction, and high impact to confidentiality, integrity, and availability.
- Vendor
- Microsoft
- Product
- Microsoft 365 Apps for Enterprise
- CVSS
- HIGH 8.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-07-08
- Original CVE updated
- 2025-07-15
- Advisory published
- 2025-07-08
- Advisory updated
- 2025-07-15
Who should care
Security and IT teams managing Microsoft Office deployments, especially Microsoft 365 Apps enterprise, Office 2016/2019, Office LTSC 2021, Office LTSC 2024, and Office for Android/macOS where applicable.
Technical summary
The NVD record classifies CVE-2025-49696 as CWE-125 (out-of-bounds read), with Microsoft also listing CWE-122 as a secondary weakness. The published CVSS vector is CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a locally exploitable issue with no privileges or user interaction required and potentially high impact if triggered in an affected Office installation. The NVD vulnerable CPE set includes Microsoft 365 Apps enterprise (x86/x64), Office 2016, Office 2019, Office LTSC 2021, and Office LTSC 2024 across x86/x64 and macOS variants, plus Office for Android.
Defensive priority
High
Recommended defensive actions
- Install the Microsoft update referenced in the vendor advisory for CVE-2025-49696.
- Prioritize remediation on endpoints running the affected Office editions and channels listed in the NVD record.
- Verify that Microsoft 365 Apps enterprise, Office 2016/2019, Office LTSC 2021/2024, and any deployed Office for Android/macOS builds are covered by the applicable update.
- Track Microsoft and NVD updates for any change in vulnerability scope or remediation guidance.
Evidence notes
This debrief is based on the supplied NVD record and the Microsoft Security Response Center advisory linked from that record. The CVE was published on 2025-07-08 and modified on 2025-07-15. The supplied corpus does not include a CISA KEV entry or any confirmed ransomware association.
Official resources
-
CVE-2025-49696 CVE record
CVE.org
-
CVE-2025-49696 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
Published 2025-07-08 and modified 2025-07-15 in the supplied CVE/NVD record; Microsoft advisory is referenced by NVD. No KEV listing is present in the supplied data.