← back
CVE-2025-47173highCWE-641

Microsoft Office Remote Code Execution Vulnerability

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.8epss 0.5%
exploitation probability
0.5%top 58% of all CVEs
observed exploitation
nono source reports it
In short

Microsoft Office fails to properly check user-provided files, allowing an attacker to execute malicious code on your computer when you open a specially crafted document. This is dangerous because it gives the attacker complete control of your system.

Technical detail

CWE-641 improper input validation in Microsoft Office enables arbitrary code execution through a local attack vector when processing maliciously crafted files. The vulnerability requires user interaction (opening a document) and results in code execution with the privileges of the affected Office process.

Summary generated and translated by AI from the official description.
Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C