CVE-2025-55243 is a high-severity information exposure vulnerability affecting Microsoft Office Plus, enabling an unauthorized attacker to perform network spoofing. With a CVSS score of 7.5, this vulnerability is easily exploitable over a network without user interaction, potentially leading to the disclosure of sensitive information. While not currently listed on the KEV catalog or having public exploit code, its high FAUCET Risk Score of 72/100 and mentions in community discussions and media coverage suggest it warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.10.0.26585CPE matchmatch criteria | cpe:2.3:a:microsoft:officeplus:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.