Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2025-21383

Опубликовано: 11 фев. 2025
Источник: msrc
CVSS3: 7.8
EPSS Низкий

Описание

Microsoft Excel Information Disclosure Vulnerability

FAQ

What type of information could be disclosed by this vulnerability?

An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.

How could an attacker exploit this vulnerability?

To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.

Additionally, an attacker could convince a local user to open a malicious file. The attacker would have to convince the user to click a link, typically by way of an enticement in an email or instant message, and then convince them to open the specially crafted file.

Is the Preview Pane an attack vector for this vulnerability?

No, the Preview Pane is not an attack vector.

Обновления

ПродуктСтатьяОбновление
Microsoft Excel 2016 (32-bit edition)
Microsoft Excel 2016 (64-bit edition)
Microsoft Office 2019 for 32-bit editions
-
Microsoft Office 2019 for 64-bit editions
-
Microsoft 365 Apps for Enterprise for 32-bit Systems
-
Microsoft 365 Apps for Enterprise for 64-bit Systems
-
Microsoft Office LTSC for Mac 2021
Microsoft Office LTSC 2021 for 64-bit editions
-
Microsoft Office LTSC 2021 for 32-bit editions
-
Microsoft Office LTSC 2024 for 32-bit editions
-

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 32%
0.00121
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
7 месяцев назад

Microsoft Excel Information Disclosure Vulnerability

CVSS3: 7.8
github
7 месяцев назад

Microsoft Excel Information Disclosure Vulnerability

CVSS3: 7.8
fstec
7 месяцев назад

Уязвимость пакетов программ Microsoft Office, Excel и 365 Apps for Enterprise, связанная с чтением за пределами допустимого диапазона в памяти, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 32%
0.00121
Низкий

7.8 High

CVSS3