[German]On June 10, 2025 (second Tuesday of the month, Microsoft Patchday), Microsoft released several security-related updates for Microsoft Office 2016, as well as the C2R variants (Office 2016-2021 and 365) and other products. This month, serious vulnerabilities in Office were closed. Below you will find an overview of the available updates.
An overview of the updates can be found on this website (and here for this month). Details are documented in the linked KB articles. The updates are available for the installable MSI version of Microsoft Office (the Click-to-Run packages receive the updates via other channels). Office 2019/2021/2024 do not appear in the list as they are distributed via Click-to-Run packages and receive security updates via the Office Update feature.
Vulnerabilities in Office
In Microsoft Office, the remote code execution vulnerabilities CVE-2025-47162, CVE-2025-47164, CVE-2025-47167, and CVE-2025-47953 have been closed by the updates (see also Microsoft Security Update Summary (June 10, 2025)). The vulnerabilities were classified as critical with a CVEv3 score of 8.4. With the exception of CVE-2025-47953, a display in the preview window is sufficient as an attack vector to exploit these vulnerabilities. Microsoft therefore rates the exploitability as "Exploitation More Likely".
Office 2016
The following security updates have been released for Microsoft Office 2016.
- KB5002735: Security update for Excel 2016, which closes the RCE vulnerability CVE-2025-47165. There is a known issue that when opening a workbook outside of Excel, an error message appears for file names that contain square brackets [ ]. The bracket in the file name must then be removed.
- KB5002616: Security update for Office 2016 that closes the RCE vulnerability CVE-2025-47167.
- KB5002730: Security update for Office 2016, which closes the RCE vulnerabilities CVE-2025-47162, CVE-2025-47164, CVE-2025-47173 and CVE-2025-47953.
- KB5002683: Security update for Outlook 2016, which closes the RCE vulnerability CVE-2025-47171.
- KB5002689: Security update for PowerPoint 2016, which closes the RCE vulnerability CVE-2025-47175–
- KB5002710: Security update for Word 2016, which closes the RCE vulnerabilities CVE-2025-47168 and CVE-2025-47169 schließt.
Details on the Office updates and the direct download addresses for the updates can be found in the linked KB articles.
Office C2R Updates
For the Click-2-Run installation packages, the updates are obtained and installed directly via the respective Office package. According to this Microsoft website, the following security updates have been released:
- Current Channel: Version 2505 (Build 18827.20150)
- Monthly Enterprise Channel: Version 2504 (Build 18730.20220)
- Monthly Enterprise Channel: Version 2503 (Build 18623.20298)
- Monthly Enterprise Channel: Version 2502 (Build 18526.20416)
- Semi-Annual Enterprise Channel (Preview): Version 2502 (Build 18526.20416)
- Semi-Annual Enterprise Channel: Version 2408 (Build 17928.20572)
- Semi-Annual Enterprise Channel: Version 2402 (Build 17328.20820)
- Office 2024 Retail: Version 2505 (Build 18827.20150)
- Office 2021 Retail: Version 2505 (Build 18827.20150)
- Office 2019 Retail: Version 2505 (Build 18827.20150)
- Office 2016 Retail: Version 2505 (Build 18827.20150)
- Office LTSC 2024 Volume Licensed: Version 2408 (Build 17932.20396)
- Office LTSC 2021 Volume Licensed: Version 2108 (Build 14334.20090)
- Office 2019 Volume Licensed: Version 1808 (Build 10417.20020)
The website linked above lists the fixed vulnerabilities for individual Office modules. For volume licenses, the respective builds are listed on this Microsoft site.
Updates for Office/SharePoint Server
Microsoft has also released security updates for various versions of Microsoft SharePoint Server.
SharePoint Server-Abonnementedition
- SharePoint Server Subscription Edition: KB5002736
Microsoft SharePoint Server 2019
Microsoft SharePoint Server 2016
- SharePoint Enterprise Server 2016: KB5002732
- SharePoint Enterprise Server 2016 Language Pack: KB5002731
Office Online Server
- Office Online Server: KB5002728
Similar articles:
Microsoft Security Update Summary (June 10, 2025)
Patchday: Windows 10/11 Updates (June 10, 2025)
Patchday: Windows Server-Updates (June 10, 2025)
Patchday: Microsoft Office Updates (June 10, 2025)
Windows 10/11: Preview Updates May 27, 28,2025
Attention: June 2025 Patchday closes vulnerability CVE-2025-33073 in Windows