CVE-2025-47994: Microsoft Office Elevation of Privilege Vulnerability
Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.
Other sources
Microsoft Office Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47994?
CVE-2025-47994 is classified as an Elevation of Privilege vulnerability in Microsoft Office.
What systems are affected by CVE-2025-47994?
CVE-2025-47994 affects several Microsoft Office products including Office 2016, Office 2019, Office LTSC 2021, and Microsoft 365 Apps.
How do I fix CVE-2025-47994?
To fix CVE-2025-47994, ensure that your Microsoft Office software is updated to the latest version with the appropriate security patches.
What types of attacks can CVE-2025-47994 enable?
CVE-2025-47994 can enable unauthorized attackers to elevate their privileges locally on affected systems.
Is CVE-2025-47994 due to a coding error?
Yes, CVE-2025-47994 is related to the deserialization of untrusted data in Microsoft Office, which is a coding error in the handling of data.