CVE-2025-21345

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 416

Summary

CVE-2025-21345 is a remote code execution vulnerability affecting Microsoft Office Visio. Attackers can exploit this issue by persuading a user to open a specially crafted Visio file, resulting in arbitrary code execution on the targeted system. Successful exploitation permits the attacker to gain the same privileges as the user, potentially leading to significant security risks and data breaches. Users are advised to install the latest security updates and be cautious when opening untrusted files.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share