Spoofing Vulnerability in Microsoft Office Plus Affects User Data
CVE-2025-55243

7.5HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
9 September 2025

What is CVE-2025-55243?

A vulnerability in Microsoft Office Plus enables unauthorized actors to exploit the system, leading to unauthorized access and exposure of sensitive user information. This could allow attackers to impersonate trusted entities over the network, potentially compromising the security and integrity of communications.

Affected Version(s)

Microsoft OfficePLUS Unknown 3.0.0.0 < 3.10.0.26585

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.