CVE-2025-47171

Published Jun 10, 2025

Last updated 8 days ago

Overview

Description
Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.
Source
secure@microsoft.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Secondary
Base score
6.7
Impact score
5.9
Exploitability score
0.8
Vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Severity
MEDIUM

Weaknesses

secure@microsoft.com
CWE-20

Social media

Hype score
Not currently trending
  1. nu11secur1ty: CVE-2025-47171-Microsoft Outlook Remote Code Execu... https://t.co/C1bKwthbYQ Third-level programmers

    @nu11secur1ty1

    10 Jul 2025

    169 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Actively exploited CVE : CVE-2025-47171

    @transilienceai

    18 Jun 2025

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. Actively exploited CVE : CVE-2025-47171

    @transilienceai

    15 Jun 2025

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. Actively exploited CVE : CVE-2025-47171

    @transilienceai

    15 Jun 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. Actively exploited CVE : CVE-2025-47171

    @transilienceai

    14 Jun 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. Actively exploited CVE : CVE-2025-47171

    @transilienceai

    14 Jun 2025

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. Actively exploited CVE : CVE-2025-47171

    @transilienceai

    13 Jun 2025

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  8. Actively exploited CVE : CVE-2025-47171

    @transilienceai

    12 Jun 2025

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  9. Actively exploited CVE : CVE-2025-47171

    @transilienceai

    12 Jun 2025

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  10. Yesterday, Microsoft patched two Remote Code Execution vulnerabilities in Outlook that we discovered. 🙃 1. CVE-2025-47171 --> https://t.co/qG4fzy69Jw 2. CVE-2025-47176 --> https://t.co/mjzDoMhmGX ⚠️ More findings on the way — stay tuned.

    @osipov_ar

    11 Jun 2025

    2641 Impressions

    6 Retweets

    35 Likes

    18 Bookmarks

    1 Reply

    0 Quotes

  11. 🔒 Outlook's got a new party crasher: CVE-2025-47171! This remote code execution vulnerability turns your inbox into a hacker's playground. Time to tighten those security settings! #WindowsForum #Outlook #Cybersecurity https://t.co/I3fQSJO2so

    @windowsforum

    10 Jun 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.