CVE-2025-21354
CVSS 3.1 Score 8.4 of 10 (high)
Details
Published Jan 14, 2025
Updated: Jan 15, 2025
CWE ID 822
Summary
CVE-2025-21354 is a Remote Code Execution vulnerability affecting Microsoft Excel. Attackers can exploit this weakness by tricking users into opening a specially crafted Excel file. Successful exploitation allows the attacker to run arbitrary code in the context of the Excel application, potentially leading to significant security risks. This vulnerability underscores the importance of keeping software up-to-date to protect against known threats. Users are advised to apply the relevant Microsoft security patch as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Office
- Microsoft Office Excel
- Microsoft 365 Apps
Affected Vendors
- Microsoft