CVE-2025-47174 is a high-severity heap-based buffer overflow vulnerability in Microsoft Office Excel, affecting Microsoft 365 Apps and Office Long Term Servicing Channel. This flaw allows an unauthenticated attacker to execute code locally, requiring user interaction. While not currently listed in CISA's KEV catalog, its high CVSS score of 7.8 and FAUCET Risk Score of 75/100 indicate significant potential impact. There is no public exploit code available, but community discussion and media coverage suggest awareness, with one article mentioning it as a fix in the June 2025 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:*:* | ||
2021CPE matchmatch criteria | cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:*:*:* | ||
2024CPE matchmatch criteria | cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.