7.5
CVE-2025-29816
- EPSS 0.13%
- Veröffentlicht 08.04.2025 17:24:18
- Zuletzt bearbeitet 09.07.2025 16:58:52
- Quelle secure@microsoft.com
- CVE-Watchlists
- Unerledigt
Microsoft Word Security Feature Bypass Vulnerability
Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Office Long Term Servicing Channel Version2021 SwPlatform-
Microsoft ≫ Office Long Term Servicing Channel Version2021 SwPlatformmacos
Microsoft ≫ Office Long Term Servicing Channel Version2024 SwPlatform-
Microsoft ≫ Office Long Term Servicing Channel Version2024 SwPlatformmacos
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.329 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| secure@microsoft.com | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-349 Acceptance of Extraneous Untrusted Data With Trusted Data
The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.