CVE-2025-26642
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Apr 8, 2025
Updated: Apr 9, 2025
CWE ID 125
CWE ID 190
Summary
CVE-2025-26642 is a newly disclosed vulnerability affecting Microsoft Office. This issue permits an unauthorized attacker to execute code locally due to an out-of-bounds read error. The error occurs when Microsoft Office fails to properly handle specially crafted data, leading to potential code execution. Successful exploitation could result in significant harm, including data theft or system compromise. Users are urged to apply the relevant patches as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.