Microsoft published security advisories for multiple information disclosure vulnerabilities affecting core productivity applications, including Microsoft Office (CVE-2022-30172), Microsoft Outlook (CVE-2023-35636), and Microsoft Excel (CVE-2025-21383, CVE-2025-59232, and CVE-2025-59235). The references indicate a recurring pattern of disclosure issues across Office components rather than a single-product defect, with Excel appearing in several separate advisories.
The advisories were issued through the Microsoft Security Response Center and Security Update Guide, signaling that patches or security guidance were made available for affected products. While the referenced entries do not include technical synopses, the affected CVEs show that organizations using Office suites should prioritize review of information disclosure exposure in document-handling and email workflows, especially in environments where Outlook and Excel are widely deployed.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
Microsoft published Security Update Guide entry CVE-2026-32188, describing an information disclosure vulnerability in Microsoft Excel caused by an out-of-bounds read. Microsoft said a fix was available and that the flaw was not publicly disclosed or exploited in the wild at publication.
Microsoft published Security Update Guide entry CVE-2025-59235, identifying another information disclosure vulnerability in Microsoft Excel.
Microsoft published Security Update Guide entry CVE-2025-59232, identifying an information disclosure vulnerability in Microsoft Excel.
Microsoft published Security Update Guide entry CVE-2025-48812, identifying an information disclosure vulnerability in Microsoft Excel.
Microsoft published CVE-2025-21383 in the Security Update Guide as an information disclosure vulnerability affecting Microsoft Excel. Duplicate references point to the same advisory publication.
Microsoft published Security Update Guide entry CVE-2023-35636, describing an information disclosure vulnerability in Microsoft Outlook.
Microsoft added CVE-2022-30172 to its Security Update Guide as an information disclosure vulnerability affecting Microsoft Office.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceportal.msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.