CVE-2025-47176
HIGH EXPLOITEDMicrosoft 365 Apps - Path Traversal
Title source: ruleDescription
'.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.
Exploits (1)
Scores
CVSS v3
7.8
EPSS
0.0123
EPSS Percentile
79.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2025-06-16
CWE
CWE-22
CWE-35
Status
published
Products (2)
microsoft/365_apps
(2 CPE variants)
microsoft/office_long_term_servicing_channel
2024 (2 CPE variants)
Published
Jun 10, 2025
Tracked Since
Feb 18, 2026