Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27352 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
Wed, 19 Nov 2025 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft office 2019
Microsoft office 2021 Microsoft office 2024 Microsoft office Macos 2021 Microsoft office Macos 2024 Microsoft sharepoint Server 2016 Microsoft sharepoint Server 2019 Microsoft word 2016 |
|
| CPEs | cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:* cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:* cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:* cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:* cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:* cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:* cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:word_2016:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft office 2019
Microsoft office 2021 Microsoft office 2024 Microsoft office Macos 2021 Microsoft office Macos 2024 Microsoft sharepoint Server 2016 Microsoft sharepoint Server 2019 Microsoft word 2016 |
Fri, 12 Sep 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft 365 Apps Microsoft office Microsoft office Long Term Servicing Channel Microsoft sharepoint Enterprise Server Microsoft sharepoint Server Microsoft word |
|
| CPEs | cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:* cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:* cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:x64:* cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:x86:* cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x64:* cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x86:* cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:macos:*:* cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x64:* cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x86:* cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:macos:*:* cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:* cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:x64:* cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:x86:* |
|
| Vendors & Products |
Microsoft
Microsoft 365 Apps Microsoft office Microsoft office Long Term Servicing Channel Microsoft sharepoint Enterprise Server Microsoft sharepoint Server Microsoft word |
Tue, 09 Sep 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Sep 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Title | Microsoft Word Information Disclosure Vulnerability | |
| Weaknesses | CWE-822 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-02-20T16:00:23.697Z
Reserved: 2025-07-31T18:54:19.612Z
Link: CVE-2025-54905
Updated: 2025-09-09T17:45:14.375Z
Status : Analyzed
Published: 2025-09-09T17:16:02.130
Modified: 2025-09-12T16:52:24.250
Link: CVE-2025-54905
No data.
OpenCVE Enrichment
No data.
EUVD