CVE Vulnerabilities

CVE-2025-21402

Improper Restriction of Names for Files and Other Resources

Published: Jan 14, 2025 | Modified: Jan 27, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Microsoft Office OneNote Remote Code Execution Vulnerability

Weakness

The product constructs the name of a file or other resource using input from an upstream component, but it does not restrict or incorrectly restricts the resulting name.

Affected Software

NameVendorStart VersionEnd Version
OfficeMicrosoft2021 (including)2021 (including)
OfficeMicrosoft2024 (including)2024 (including)
OnenoteMicrosoft- (including)- (including)

Potential Mitigations

References