CVE-2025-21346

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 693

Summary

CVE-2025-21346 is a newly disclosed Microsoft Office vulnerability that enables an attacker to bypass security features. By exploiting this weakness, an adversary can execute malicious code, potentially leading to data theft or system compromise. The issue lies in the way Microsoft Office handles certain file formats, allowing for the bypassing of security checks and enabling code execution. Organizations and individuals using Microsoft Office are urged to apply the necessary patches as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share