CVE-2025-47162
vulnerability analysis and mitigation

Overview

A heap-based buffer overflow vulnerability in Microsoft Office (CVE-2025-47162) was disclosed on June 10, 2025, as part of Microsoft's June 2025 Patch Tuesday security updates. The vulnerability allows an unauthorized attacker to execute code locally and received a CVSS v3.1 base score of 8.4 (HIGH) (NVD, Wiz).

Technical details

The vulnerability is one of four Office-related bugs where the Preview Pane is an attack vector. Specifically, it is a heap-based buffer overflow vulnerability that could allow unauthorized attackers to execute arbitrary code in the context of the current user. Microsoft has assigned their highest exploit index rating to this vulnerability, indicating they expect public exploitation within 30 days (Wiz, Help Net).

Impact

The vulnerability enables attackers to execute arbitrary code on affected systems without requiring user interaction, as the Preview Pane serves as an attack vector. When successfully exploited, attackers can potentially combine this vulnerability with privilege escalation bugs to achieve complete system compromise. The critical nature of this vulnerability and its attack vector makes it particularly dangerous in enterprise environments (Wiz).

Mitigation and workarounds

Microsoft has released patches for this vulnerability as part of their June 2025 Patch Tuesday security updates. Security experts strongly recommend immediate deployment of these Office updates due to the critical nature of the vulnerability and its expected exploitation. Organizations are advised not to delay rolling out Office updates this month given the severity and likelihood of exploitation (Wiz).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management