High severity8.4NVD Advisory· Published Jun 10, 2025· Updated Jul 9, 2025
CVE-2025-47167
CVE-2025-47167
Description
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
Affected products
9- Microsoft/Microsoft 365 Apps for Enterprisev5Range: 16.0.1
16.0.0+ 1 more
- (no CPE)range: 16.0.0
- (no CPE)range: 19.0.0
- Microsoft/Microsoft Office for Androidv5Range: 16.0.1
- Microsoft/Microsoft Office LTSC 2021v5Range: 16.0.1
- Microsoft/Microsoft Office LTSC 2024v5Range: 16.0.0
- Microsoft/Microsoft Office LTSC for Mac 2021v5Range: 16.0.1
- Microsoft/Microsoft Office LTSC for Mac 2024v5Range: 16.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47167nvdVendor Advisory
News mentions
0No linked articles in our index yet.