PatchSiren cyber security CVE debrief
CVE-2025-21402 Microsoft CVE debrief
A remote code execution vulnerability in Microsoft Office OneNote for macOS, published by Microsoft on January 14, 2025, and last modified on May 19, 2026. The vulnerability allows an attacker to execute arbitrary code on affected systems through user interaction with a malicious OneNote document. Microsoft has released patches for this vulnerability. The CVSS 3.1 score of 7.8 (HIGH) reflects local attack vector, low attack complexity, no privileges required, but requires user interaction. Affected products include Microsoft Office 2024 LTSC for macOS, Office LTSC 2021 for macOS, and OneNote for macOS. The weakness is associated with CWE-641 (Improper Restriction of Names for Files and Other Resources) per Microsoft's advisory, though NVD lists it as NVD-CWE-noinfo.
- Vendor
- Microsoft
- Product
- Microsoft Office LTSC for Mac 2021
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-01-14
- Original CVE updated
- 2026-05-19
- Advisory published
- 2025-01-14
- Advisory updated
- 2026-05-19
Who should care
Organizations using Microsoft Office 2024 LTSC, Office LTSC 2021, or OneNote on macOS; security teams managing macOS endpoint protection; users who exchange OneNote documents externally
Technical summary
This vulnerability in Microsoft OneNote for macOS permits remote code execution when a user opens a specially crafted OneNote document. The attack requires local access context (AV:L) but no privileges, with successful exploitation yielding high impact to confidentiality, integrity, and availability. The underlying weakness relates to improper handling of file or resource names (CWE-641).
Defensive priority
HIGH
Recommended defensive actions
- Apply Microsoft security updates for Office 2024 LTSC, Office LTSC 2021, and OneNote for macOS as referenced in the Microsoft Security Response Center advisory
- Educate users to avoid opening OneNote files from untrusted sources
- Consider application control policies to restrict execution of untrusted Office documents on macOS endpoints
- Monitor for suspicious OneNote-related process execution on macOS systems
Evidence notes
CVE published 2025-01-14; modified 2026-05-19. CVSS 3.1 vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. Affected CPEs confirm macOS-specific Office and OneNote versions. Microsoft tags reference as 'Patch, Vendor Advisory'.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-21402 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-21402
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-21402 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-21402
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21402
[email protected] - Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.