ZeroHour

CVE-2025-49702

CVSS 3.1
7.8 high
EPSS
<1%p47
Published
()
Modified
Description

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Vendors
microsoft
Products
365 apps, 365 copilot, office, office long term servicing channel
Weakness
CWE-843
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news