Home
HIGH: 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 16.0.1 (custom) before https://aka.ms/OfficeSecurityReleases
affected
19.0.0 (custom) before https://aka.ms/OfficeSecurityReleases
affected
16.0.1 (custom) before https://aka.ms/OfficeSecurityReleases
affected
16.0.0 (custom) before https://aka.ms/OfficeSecurityReleases
affected
16.0.1 (custom) before 16.96.25041326
affected
16.0.0 (custom) before 16.96.25041326
affected
1.0.0 (custom) before 16.96.25033028
affected
16.0.0 (custom) before 16.0.5495.1001
affected
Description
Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally.
Problem types
CWE-184: Incomplete List of Disallowed Inputs
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29822 (Microsoft OneNote Security Feature Bypass Vulnerability)