Remote Code Execution Vulnerability in Microsoft Office OneNote
CVE-2025-21402

7.8HIGH

Key Information:

Summary

A vulnerability exists in Microsoft Office OneNote that could allow an attacker to execute arbitrary code on the user's machine. By crafting a malicious file and enticing a user to open it, an attacker could take control of the affected system. Users are advised to apply security updates promptly to mitigate the risk associated with this vulnerability.

Affected Version(s)

Microsoft Office LTSC for Mac 2021 Unknown 16.0.1 < 16.93.25011212

Microsoft Office LTSC for Mac 2024 Unknown 1.0.0 < 16.93.25011212

Microsoft OneNote Unknown 1.0.0 < 16.92.24120731

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.