KEVIntel
8.4
CVSS
High

CVE-2025-47162

PUBLISHED

Microsoft Office Remote Code Execution Vulnerability

Exploited in the wild Low complexity No user interaction
Vendor
Microsoft
Product
Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office for Android, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024
Published
Jun 10, 2025
EPSS

Description

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS scores

CVSS v3.1 8.4 High

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Exploitation status

Exploited in the wild

Recorded 2025-06-11 07:01:39 UTC · Source

SSVC decision points

Exploitation
none
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
The Shadowserver (via CIRCL) Jun 11, 2025

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel