7.5

CVE-2025-29816

Microsoft Word Security Feature Bypass Vulnerability

Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ 365 Apps Version - SwEdition enterprise
Microsoft ≫ Office Version 2016
Microsoft ≫ Office Version 2019
Microsoft ≫ Office Long Term Servicing Channel Version 2021 SwPlatform -
Microsoft ≫ Office Long Term Servicing Channel Version 2021 SwPlatform macos
Microsoft ≫ Office Long Term Servicing Channel Version 2024 SwPlatform -
Microsoft ≫ Office Long Term Servicing Channel Version 2024 SwPlatform macos
Microsoft ≫ Word Version 2016
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.44% 0.357
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Microsoft 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-349 Acceptance of Extraneous Untrusted Data With Trusted Data

The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29816
Vendor Advisory