Cross-Site Scripting Vulnerability in Microsoft Office Out-of-Box Experience
CVE-2025-64677
8.2HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 18 December 2025
What is CVE-2025-64677?
The vulnerability in the Office Out-of-Box Experience allows attackers to exploit improper input handling during web page generation. This could lead to unauthorized access and spoofing over a network, posing significant security risks to users. Attackers can manipulate the application's response to execute malicious scripts within the context of the user's browser.
Affected Version(s)
Office Out-of-Box Experience Unknown