CVE-2025-32717

Published Jun 11, 2025

Last updated a day ago

CVSS high 8.4
Microsoft Office Word

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-32717 is a heap-based buffer overflow vulnerability in Microsoft Office Word. It allows an unauthorized attacker to execute code locally on a vulnerable system. The vulnerability can be exploited through a maliciously crafted RTF file, which could be triggered via the Preview Pane without requiring user interaction. Successful exploitation of this vulnerability could allow an attacker to compromise the system. A security update was released on June 10, 2025, to address this vulnerability in Microsoft 365 Apps.

Description
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Source
secure@microsoft.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Primary
Base score
8.4
Impact score
5.9
Exploitability score
2.5
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-122

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

18

  1. 2025-06-12 の人気記事はコチラでした。(自動ツイート) #Hacker_Trends ――― CVE-2025-32717 - Security Update Guide - Microsoft - Microsoft Word Remote Code Execution Vulnerability https://t.co/QwqotgY5E8 https://t.co/urcMTMRh2V

    @motikan2010

    13 Jun 2025

    97 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ⚠️Actualizaciones de seguridad de junio de Microsoft ❗CVE-2025-33053 ❗CVE-2025-33073 ❗CVE-2025-32717 ❗CVE-2025-29828 ➡️Más info: https://t.co/GkinGPK48t https://t.co/YP7m2cOCO8

    @CERTpy

    12 Jun 2025

    173 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2025-32717 Microsoft Word Remote Code Execution Vulnerability https://t.co/zBEDRrdzkY

    @Dinosn

    11 Jun 2025

    6623 Impressions

    32 Retweets

    106 Likes

    42 Bookmarks

    0 Replies

    3 Quotes

  4. Hey, for folks tracking today's Microsoft bugs, there's one more interesting entry that was published later today, so you might have missed it. CVE-2025-32717 is a bug I recently discovered and received a very quick patch. It's rated "Critical" and it's an easy heap-based buffer

    @HaifeiLi

    11 Jun 2025

    5721 Impressions

    12 Retweets

    40 Likes

    19 Bookmarks

    0 Replies

    0 Quotes

  5. ⚠️ High-severity CVE-2025-32717: Heap-based buffer overflow in Microsoft 365 Apps lets attackers execute code. Patch now! Details: https://t.co/bt0p9XPMG3 #OffSeq #Cybersecurity #Microsoft365 #CVE202532717 https://t.co/Y29Cfd609B

    @offseq

    11 Jun 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. [CVE-2025-32717: HIGH] Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.#cve,CVE-2025-32717,#cybersecurity https://t.co/RH0b08F8Vq https://t.co/sKg8ykHZTE

    @CveFindCom

    10 Jun 2025

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.