CVE-2025-53732: Microsoft 365 Copilot

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected products

  • Microsoft 365 Copilot: before 16.0.19127.20000 (fixed in 16.0.19127.20000)
  • Microsoft Office: before 16.0.14326.22618 (fixed in 16.0.14326.22618)

Published 2025-08-12. Last modified 2026-06-17.