Mitigating CVE-2025-22944 Remote Code Execution Vulnerability in Microsoft 365 Apps for Enterprise

Lakin Marquieta 80 Reputation points
2025-09-30T06:35:33.23+00:00

We manage Microsoft 365 Apps for Enterprise (Version 2409, Build 16829.20234) across 250 Windows 10/11 endpoints in an enterprise environment with Defender for Endpoint and Configuration Manager. Following the disclosure of CVE-2025-22944, a critical remote code execution vulnerability (CVSS 8.8) in Microsoft Office, we are urgently addressing risks from malicious file exploitation, which could allow attackers to execute arbitrary code or steal data.

The August 2025 security update (KB5063224) is queued for deployment, but we seek clarification to ensure robust mitigation.

Our environment includes mixed Office versions (Microsoft 365 Apps and Office LTSC 2021) with heavy use of Word/Excel for macro-enabled documents shared via OneDrive and Outlook.

Microsoft 365 and Office | Development | Microsoft 365 App Publishing
0 comments No comments
{count} votes

Answer accepted by question author
  1. Matthew-P 7,535 Reputation points Microsoft External Staff Moderator
    2025-09-30T07:42:45.0533333+00:00

    Hi Lakin Marquieta,

    Welcome to Microsoft Q&A Forum!

    Have a good day and hope you're doing well!

    Thank you for sharing the details about the issue you're facing with CVE-2025-22944 in your Microsoft 365 Apps environment. I completely understand and empathize with your concern. This is a serious RCE vulnerability, especially in a system with 250 endpoints involving many macro-enabled documents, and deploying the KB5063224 patch requires support from tools like Defender for Endpoint (for monitoring and blocking unusual behavior) and Configuration Manager (for phased patch deployment). These tools are powerful for mitigating risks, but configuring them correctly can be complex and require specialized support.

    As a moderator of this forum, I must note that our platform cannot provide direct support for advanced technical issues like configuring Defender for Endpoint or Configuration Manager, as they involve specific enterprise environments and may require system access. I highly recommend reaching out to Microsoft Intune Support for specialized assistance, including deployment guidance and troubleshooting. They have a team of experts ready to help via ticket or call. You can contact them here: Microsoft Intune Support (select the option to create a support request).User's image

    In the meantime, while waiting for official support, here are some reliable resources from Microsoft for you to research further on Defender for Endpoint and Configuration Manager in the context of mitigating vulnerabilities like CVE-2025-22944:

    If you have any general questions about the forum, need basic advice, or if I've misunderstood anything or something is unclear, feel free to let me know. Wishing you a smooth resolution!


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".    

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.  


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.