CVE-2025-32717
published 2025-06-11CVE-2025-32717: Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
PriorityP349high8.4CVSS 3.1
AVLACLPRNUINSUCHIHAH
EPSS
0.51%
40.4th percentile
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
CVSS provenance
nvdv3.18.4HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Word Remote Code Execution Vulnerability
vendor_msrc·2025-06-10·CVSS 8.4
CVE-2025-32717 [HIGH] CWE-122 Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
Description: Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
FAQ: How could an attacker exploit this vulnerability?
An unauthenticated attacker could exploit this vulnerability by crafting a malicious RTF file. If a user opens the file or it is rendered in the preview pane, the attacker could execute arbitrary code in the user's context.
FAQ: Are the updates for the Microsoft 365 for Office currently available?
The security update for Microsoft 365 are not immediately available. The updates will be released as soon as possible, and when they are available, customers will be notified via a revision to this CVE information.
FAQ: According to the CVSS metric, the attack vector i
GHSA
GHSA-x3rj-56mr-h4q9: Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally
ghsa_unreviewed·2025-06-11
CVE-2025-32717 [HIGH] CWE-122 GHSA-x3rj-56mr-h4q9: Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday for June 2025 — Snort rules and prominent vulnerabilities
blogs_talos·2025-06-10·CVSS 8.1
CVE-2025-32717 [HIGH] Microsoft Patch Tuesday for June 2025 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for June 2025 — Snort rules and prominent vulnerabilities
Update 6/12/2025: Microsoft released an additional CVE ( CVE-2025-32717 ). Details and SIDs have been reflected to include this additional vulnerability.
Microsoft has released its monthly security update for June 2025, which includes 66 vulnerabilities affecting a range of products, including 10 that Microsoft marked as “critical.”
In this month's release, none of the included vulnerabilities have been observed by Microsoft being actively exploited in the wild. Out of eleven "critical" entries, nine are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Microsoft Windows Remote Desktop Service, Windows Schannel (Secure Channel), KDC Proxy service, Micro
Talos
Microsoft Patch Tuesday for June 2025 — Snort rules and prominent vulnerabilities
blogs_talos·2025-06-10·CVSS 8.1
CVE-2025-32717 [HIGH] Microsoft Patch Tuesday for June 2025 — Snort rules and prominent vulnerabilities
Update 6/12/2025: Microsoft released an additional CVE (CVE-2025-32717). Details and SIDs have been reflected to include this additional vulnerability.
Microsoft has released its monthly security update for June 2025, which includes 66 vulnerabilities affecting a range of products, including 10 that Microsoft marked as “critical.”
In this month's release, none of the included vulnerabilities have been observed by Microsoft being actively exploited in the wild. Out of eleven "critical" entries, nine are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Microsoft Windows Remote Desktop Service, Windows Schannel (Secure Channel), KDC Proxy service, Microsoft Office, Word and SharePoint server. There are two elevation of privilege vulnerabil
2025-06-11
Published