CVE-2025-29822: Microsoft OneNote Security Feature Bypass Vulnerability
Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally.
Other sources
Microsoft OneNote Security Feature Bypass Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.96.25041326 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.96.25033028 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5495.1001Patch KB5002622
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29822?
CVE-2025-29822 has been classified with a medium severity rating due to the potential for unauthorized access.
How do I fix CVE-2025-29822?
To fix CVE-2025-29822, install the latest security updates provided by Microsoft for affected products.
Which products are affected by CVE-2025-29822?
CVE-2025-29822 affects various Microsoft Office products including OneNote and Office LTSC versions.
Is local access required to exploit CVE-2025-29822?
Yes, an attacker needs local access to exploit CVE-2025-29822 as it involves bypassing a security feature.
Can CVE-2025-29822 affect Mac users?
Yes, CVE-2025-29822 affects Mac users running specific versions of Microsoft OneNote and Office applications.