CVE-2025-47994
published 2025-07-08CVE-2025-47994: Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.
PriorityP346high8.6CVSS 3.1
AVLACLPRNUIRSCCHIHAH
EPSS
2.81%
84.9th percentile
Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2016 | >= 16.0.0 < 16.0.5508.1001 | 16.0.5508.1001 |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2021 | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2024 | >= 16.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_office_2016 | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2024_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2024_for_64-bit_editions | — | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Office Elevation of Privilege Vulnerability
vendor_msrc·2025-07-08·CVSS 7.8
CVE-2025-47994 [HIGH] CWE-502 Microsoft Office Elevation of Privilege Vulnerability
Microsoft Office Elevation of Privilege Vulnerability
Description: Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker can successfully exploit this vulnerability by escaping the Protected View sandbox and running code at Standard User privileges.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker must send a user a malicious Office file and convince them to open it.
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
FAQ: According to the CVSS metric, the attack vector is loca
GHSA
GHSA-c957-43mv-gcvv: Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally
ghsa_unreviewed·2025-07-08
CVE-2025-47994 [HIGH] CWE-502 GHSA-c957-43mv-gcvv: Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally
Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-08
Published