{"dataType": "CVE_RECORD", "containers": {"cna": {"metrics": [{"format": "CVSS", "cvssV3_1": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.8, "attackVector": "LOCAL", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}}, {"format": "CVSS", "cvssV3_1": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 8.4, "attackVector": "LOCAL", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}}], "affected": [{"cpes": ["cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*", "cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*"], "vendor": "microsoft", "product": "365_apps", "defaultStatus": "unknown"}, {"cpes": ["cpe:2.3:a:microsoft:office:2019:*:*:*:*:-:x64:*", "cpe:2.3:a:microsoft:office:2019:*:*:*:*:-:x86:*"], "vendor": "microsoft", "product": "office", "versions": [{"status": "affected", "version": "2019"}], "defaultStatus": "unaffected"}, {"cpes": ["cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:*:x64:*", "cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:*:x86:*", "cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:*:x64:*", "cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:*:x86:*"], "vendor": "microsoft", "product": "office_long_term_servicing_channel", "versions": [{"status": "affected", "version": "2021"}, {"status": "affected", "version": "2024"}], "defaultStatus": "unaffected"}, {"cpes": ["cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:macos:*:*", "cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:macos:*:*"], "vendor": "microsoft", "product": "office_long_term_servicing_channel", "versions": [{"status": "affected", "version": "2021"}, {"status": "affected", "version": "2024"}], "platforms": ["cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*"], "defaultStatus": "unaffected"}, {"cpes": ["cpe:2.3:a:microsoft:office_online_server:*:*:*:*:*:*:*:*"], "vendor": "microsoft", "product": "office_online_server", "versions": [{"status": "affected", "version": "0", "lessThan": "16.0.10416.20047", "versionType": "custom"}], "defaultStatus": "unaffected"}], "references": [{"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21354", "tags": ["patch", "vendor-advisory"]}], "descriptions": [{"lang": "en", "value": "Microsoft Excel Remote Code Execution Vulnerability"}, {"lang": "es", "value": "Vulnerabilidad de ejecución remota de código en Microsoft Excel"}], "problemTypes": [{"descriptions": [{"lang": "en", "cweId": "CWE-822", "description": "CWE-822"}, {"lang": "en", "description": "NVD-CWE-noinfo"}]}], "x_remediations": {"windows": [{"type": "update", "anyOf": ["KB5002677", "KB5002679", "KB5002690", "KB5002699", "KB5002707", "KB5002728", "KB5002740", "KB5002752", "KB5002776", "KB5002797", "KB5002801", "KB5002817", "KB5002824", "KB5002835", "KB5002846"], "products": ["Office Online Server"]}]}, "providerMetadata": {"orgId": "00000000-0000-4000-A000-000000000003", "shortName": "nvd", "dateUpdated": "2025-01-14T18:16:00Z", "x_subShortName": "nvd"}}}, "cveMetadata": {"cveId": "CVE-2025-21354", "state": "PUBLISHED", "dateUpdated": "2025-08-25T02:11:25Z", "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8", "datePublished": "2025-01-14T18:16:00Z", "assignerShortName": "microsoft"}, "dataVersion": "5.0"}