CVE-2025-21354: 365 Apps Untrusted Pointer Dereference (CVSS 7.8)

CVE-2025-21354 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Microsoft Excel Remote Code Execution Vulnerability. EPSS estimates a 0.94% chance of exploitation in the next 30 days.

Description

Microsoft Excel Remote Code Execution Vulnerability

Metrics

CVSS 3.1 7.8/10

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Probability 0.94%

56.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Vendor Product Versions
Microsoft 365 Apps All versions
Microsoft Office 2019
Microsoft Office Long Term Servicing Channel 2021
Microsoft Office Long Term Servicing Channel 2024
Microsoft Office Online Server < 16.0.10416.20047

References

Timeline

Published Jan 14, 2025

Last Modified Jun 17, 2026

Status Analyzed

Frequently Asked Questions

What is CVE-2025-21354?
Microsoft Excel Remote Code Execution Vulnerability

How severe is CVE-2025-21354?
CVE-2025-21354 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.94% probability of exploitation in the next 30 days.

How do I fix CVE-2025-21354?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.