CVE-2025-21387

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Feb 11, 2025
Updated: Feb 19, 2025
CWE ID 416

Summary

CVE-2025-21387 is a newly disclosed remote code execution vulnerability affecting Microsoft Excel. Maliciously crafted Excel files can trigger the flaw, granting attackers the ability to execute arbitrary code on the victim's system. This vulnerability poses a significant risk, as Excel is widely used and can be easily manipulated. Successful exploitation could lead to unauthorized system access, data theft, or further malware infection. It is recommended that users update their Microsoft Office software to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share