CVE-2025-49756
published 2025-07-08CVE-2025-49756: Use of a broken or risky cryptographic algorithm in Office Developer Platform allows an authorized attacker to bypass a security feature locally.
PriorityP411low3.3CVSS 3.1
AVLACHPRLUIRSUCLILAN
EPSS
0.19%
8.2th percentile
Use of a broken or risky cryptographic algorithm in Office Developer Platform allows an authorized attacker to bypass a security feature locally.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
vendor_msrc3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Office Developer Platform Security Feature Bypass Vulnerability
vendor_msrc·2025-07-08·CVSS 3.3
CVE-2025-49756 [LOW] CWE-327 Office Developer Platform Security Feature Bypass Vulnerability
Office Developer Platform Security Feature Bypass Vulnerability
Description: Use of a broken or risky cryptographic algorithm in Office Developer Platform allows an authorized attacker to bypass a security feature locally.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
To successfully exploit this vulnerability, an attacker would need to gain elevated privileges enabling them to perform file operations in directories they would not normally be able to access or perform.
FAQ: According to the CVSS metric, the attack vector is local (AV:L), privileges are required (PR:L) and user interaction is required (UI:R). How could an attacker exploit this security feature bypass vulnerability?
The attack itself is carried out loc
GHSA
GHSA-gfj7-mwjw-jmhf: Use of a broken or risky cryptographic algorithm in Office Developer Platform allows an authorized attacker to bypass a security feature locally
ghsa_unreviewed·2025-07-08
CVE-2025-49756 [LOW] CWE-327 GHSA-gfj7-mwjw-jmhf: Use of a broken or risky cryptographic algorithm in Office Developer Platform allows an authorized attacker to bypass a security feature locally
Use of a broken or risky cryptographic algorithm in Office Developer Platform allows an authorized attacker to bypass a security feature locally.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-08
Published