Microsoft Office OneNote Remote Code Execution Vulnerability
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.8epss 0.7%
exploitation probability
0.7%top 52% of all CVEs
observed exploitation
nono source reports it
In short
Microsoft OneNote has a vulnerability that allows attackers to execute malicious code on your computer when you open a specially crafted document. This is dangerous because it gives attackers full control over your system.
Technical detail
CWE-641 vulnerability in OneNote allows remote code execution through crafted files that exploit improper handling of embedded objects or external references. Attack requires user interaction (document opening) and results in code execution with user privileges; no authentication bypass or elevated privileges required for initial compromise.
Summary generated and translated by AI from the official description.
Microsoft Office OneNote Remote Code Execution Vulnerability
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RC:C