CVE-2025-47953
HIGHDescription
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Is your site exposed to CVE-2025-47953?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| microsoft | 365_apps |
| microsoft | office |
| microsoft | office |
| microsoft | office |
| microsoft | office_long_term_servicing_channel |
| microsoft | office_long_term_servicing_channel |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-47953? +
How severe is CVE-2025-47953? +
What products are affected by CVE-2025-47953? +
How do I check if I'm vulnerable to CVE-2025-47953? +
Related Vulnerabilities
Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Office OneNote Remote Code Execution Vulnerability
Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally.
Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.
In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing …
Windows Distributed File System (DFS) Remote Code Execution Vulnerability