Improper Input Validation in Microsoft Outlook by Microsoft
CVE-2025-47171

6.7MEDIUM

Key Information:

Badges

👾 Exploit Exists📰 News Worthy

What is CVE-2025-47171?

A vulnerability exists in Microsoft Office Outlook due to improper input validation, allowing an attacker with valid credentials to execute arbitrary code on the affected system. This issue highlights the necessity for robust input validation mechanisms to prevent unauthorized actions and maintain system integrity. For further details and guidance, refer to Microsoft's official advisory.

Affected Version(s)

Microsoft 365 Apps for Enterprise 32-bit Systems 16.0.1

Microsoft Office 2019 32-bit Systems 19.0.0

Microsoft Office LTSC 2021 x64-based Systems 16.0.1

News Articles

Microsoft Patches Two New RCE Vulnerabilities: CVE-2025-47171 and CVE-2025-47176 

Morphisec Threat Labs discovers and details two severe Microsoft Outlook vulnerabilities: CVE-2025-47171 and CVE-2025-47176.

16 hours ago

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by Morphisec

  • Vulnerability published

  • Vulnerability Reserved

.