CVE-2025-47977 is a high-severity cross-site scripting (XSS) vulnerability (CVSS 8.2) affecting Microsoft Nuance Digital Engagement Platform. An unauthenticated attacker can exploit this flaw over a network with low complexity, requiring user interaction, to achieve high confidentiality impact and limited integrity impact, enabling spoofing. While not currently in CISA's KEV catalog and lacking public exploit code, it has garnered some community discussion and media coverage, including a mention in a BleepingComputer article regarding Microsoft's June 2025 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.64.xCPE matchmatch criteria | cpe:2.3:a:microsoft:nuance_digital_engagement_platform:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.