CVE-2025-47953: high-severity vulnerability in Microsoft 365 Apps for Enterprise
Microsoft Office Remote Code Execution Vulnerability
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
Microsoft Office has a flaw that lets an attacker run harmful code on your computer by exploiting how the program manages memory. This happens when Office tries to use data that has already been deleted, creating an opening for malicious actions.
A use-after-free vulnerability in Microsoft Office memory management allows local code execution when an attacker provides specially crafted input that causes the application to access freed memory regions. The vulnerability requires user interaction to open a malicious document and results in arbitrary code execution with the privileges of the Office process.
In the same product, most dangerous first.