CVE-2025-47173: high-severity vulnerability in Microsoft 365 Apps for Enterprise
Microsoft Office Remote Code Execution Vulnerability
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.8epss 0.6%
exploitation probability
0.6%top 54% of all CVEs
observed exploitation
nono source reports it
In short
Microsoft Office fails to properly check user-provided files, allowing an attacker to execute malicious code on your computer when you open a specially crafted document. This is dangerous because it gives the attacker complete control of your system.
Technical detail
CWE-641 improper input validation in Microsoft Office enables arbitrary code execution through a local attack vector when processing maliciously crafted files. The vulnerability requires user interaction (opening a document) and results in code execution with the privileges of the affected Office process.
Summary generated and translated by AI from the official description.
Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected products
Microsoft · Microsoft 365 Apps for EnterpriseMicrosoft · Microsoft Office 2016Microsoft · Microsoft Office 2019Microsoft · Microsoft Office LTSC 2021Microsoft · Microsoft Office LTSC 2024Microsoft · Microsoft Office LTSC for Mac 2021Microsoft · Microsoft Office LTSC for Mac 2024Related CVEs — Microsoft 365 Apps for Enterprise
In the same product, most dangerous first.
CVE-2023-23397CRITICALMicrosoft Outlook Elevation of Privilege VulnerabilityEPSS 97.2%KEVCVE-2024-21413CRITICALMicrosoft Outlook Remote Code Execution VulnerabilityEPSS 94.7%KEVCVE-2026-21509HIGHMicrosoft Office Security Feature Bypass VulnerabilityEPSS 70.8%KEVCVE-2021-42292HIGHMicrosoft Excel Security Feature Bypass VulnerabilityEPSS 43.0%KEVCVE-2023-36761MEDIUMMicrosoft Word Information Disclosure VulnerabilityEPSS 19.6%KEVCVE-2023-35311HIGHMicrosoft Outlook Security Feature Bypass VulnerabilityEPSS 15.5%KEV