NEXUS8
by 8bitsecurity
Search
Signal
Radar
IOCs
Watchlist
Sign in
Premium
Search
Signal
Radar
IOCs
Watchlist
Sign in
Premium
Search
/
CVE-2025-21402
● CVE — High
CVE-2025-21402
Microsoft Office OneNote Remote Code Execution Vulnerability
View graph
Watch
Export
CVSS v3.1
7.8
HIGH
EPSS
0.65
%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
CVSS v3.1 Detail
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Connections
4 relationships
Affects
3
Classification
1
office
source
office long term servicing channel
source
onenote
source
Timeline
disclosure → media coverage
Jan 14, 2025
Disclosure
— published as a CVE record.
· last revised by NVD May 19, 2026