PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-49696 Microsoft CVE debrief

CVE-2025-49696 is a Microsoft Office vulnerability described as an out-of-bounds read that may allow an unauthorized attacker to execute code locally. NVD assigns it CVSS 8.4 (HIGH) with local attack vector, no privileges required, no user interaction, and high impact to confidentiality, integrity, and availability.

Vendor
Microsoft
Product
Microsoft 365 Apps for Enterprise
CVSS
HIGH 8.4
CISA KEV
Not listed in stored evidence
Original CVE published
2025-07-08
Original CVE updated
2025-07-15
Advisory published
2025-07-08
Advisory updated
2025-07-15

Who should care

Security and IT teams managing Microsoft Office deployments, especially Microsoft 365 Apps enterprise, Office 2016/2019, Office LTSC 2021, Office LTSC 2024, and Office for Android/macOS where applicable.

Technical summary

The NVD record classifies CVE-2025-49696 as CWE-125 (out-of-bounds read), with Microsoft also listing CWE-122 as a secondary weakness. The published CVSS vector is CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a locally exploitable issue with no privileges or user interaction required and potentially high impact if triggered in an affected Office installation. The NVD vulnerable CPE set includes Microsoft 365 Apps enterprise (x86/x64), Office 2016, Office 2019, Office LTSC 2021, and Office LTSC 2024 across x86/x64 and macOS variants, plus Office for Android.

Defensive priority

High

Recommended defensive actions

  • Install the Microsoft update referenced in the vendor advisory for CVE-2025-49696.
  • Prioritize remediation on endpoints running the affected Office editions and channels listed in the NVD record.
  • Verify that Microsoft 365 Apps enterprise, Office 2016/2019, Office LTSC 2021/2024, and any deployed Office for Android/macOS builds are covered by the applicable update.
  • Track Microsoft and NVD updates for any change in vulnerability scope or remediation guidance.

Evidence notes

This debrief is based on the supplied NVD record and the Microsoft Security Response Center advisory linked from that record. The CVE was published on 2025-07-08 and modified on 2025-07-15. The supplied corpus does not include a CISA KEV entry or any confirmed ransomware association.

Official resources

Published 2025-07-08 and modified 2025-07-15 in the supplied CVE/NVD record; Microsoft advisory is referenced by NVD. No KEV listing is present in the supplied data.