Junglewise Threat Intelligence

CVE-2025-47162: Microsoft Office heap buffer overflow allows local code execution

CVE-2025-47162 · Severity: high · CVSS 8.4 · Published 2025-06-10

Technologies: Microsoft Office LTSC 2024, Microsoft Office for Android, Microsoft Office LTSC 2021, Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Office, a widely used suite of productivity applications. An attacker with local access to a system could exploit this flaw to run unauthorized code, potentially leading to a full system takeover or theft of sensitive documents. This impact is significant as it bypasses standard security boundaries within the application to compromise the underlying device.

Technical details

This vulnerability is classified as a heap-based buffer overflow (CWE-122) within Microsoft Office. It is triggered when the application improperly handles data in memory, allowing an attacker to overwrite adjacent memory locations. The attack vector is local, meaning an attacker must already have a presence on the system or entice a user to run a malicious file. Successful exploitation allows for arbitrary code execution with the privileges of the user running the Office application. Affected versions include Office 2016, 2019, LTSC 2021/2024, and Microsoft 365 Apps across Windows, macOS, and Android platforms.

Affected products

  • Microsoft Office 2016
  • Microsoft Office 2019
  • Microsoft Office LTSC 2021
  • Microsoft Office LTSC 2024
  • Microsoft 365 Apps for Enterprise
  • Microsoft Office for Android

Timeline

  • 2025-06-10: disclosed: Initial disclosure by Microsoft Corporation
  • 2025-06-10: advisory: NVD entry published

References

Related threats