CVE-2025-59233

HIGH

Microsoft 365 Apps < 16.0.10417.20059 - Type Confusion

Title source: rule

Description

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Scores

CVSS v3 7.8
EPSS 0.0026
EPSS Percentile 49.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-843
Status published

Affected Products (13)

microsoft/365_apps
microsoft/365_apps
microsoft/excel
microsoft/excel
microsoft/office
microsoft/office
microsoft/office_long_term_servicing_channel
microsoft/office_long_term_servicing_channel
microsoft/office_long_term_servicing_channel
microsoft/office_long_term_servicing_channel
microsoft/office_long_term_servicing_channel
microsoft/office_long_term_servicing_channel
microsoft/office_online_server < 16.0.10417.20059

Timeline

Published Oct 14, 2025
Tracked Since Feb 18, 2026