PT-2025-28525 · Microsoft · Office
Ben Faull
·
Published
2025-07-08
·
Updated
2025-08-30
·
CVE-2025-47994
CVSS v3.1
8.6
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Microsoft Office (affected versions not specified)
Description:
The issue concerns the deserialization of untrusted data in Microsoft Office, which allows an unauthorized attacker to elevate privileges locally. This means an attacker can gain higher access levels on the system, potentially leading to further malicious activities.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office