PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-21402 Microsoft CVE debrief

A remote code execution vulnerability in Microsoft Office OneNote for macOS, published by Microsoft on January 14, 2025, and last modified on May 19, 2026. The vulnerability allows an attacker to execute arbitrary code on affected systems through user interaction with a malicious OneNote document. Microsoft has released patches for this vulnerability. The CVSS 3.1 score of 7.8 (HIGH) reflects local attack vector, low attack complexity, no privileges required, but requires user interaction. Affected products include Microsoft Office 2024 LTSC for macOS, Office LTSC 2021 for macOS, and OneNote for macOS. The weakness is associated with CWE-641 (Improper Restriction of Names for Files and Other Resources) per Microsoft's advisory, though NVD lists it as NVD-CWE-noinfo.

Vendor
Microsoft
Product
Microsoft Office LTSC for Mac 2021
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-01-14
Original CVE updated
2026-05-19
Advisory published
2025-01-14
Advisory updated
2026-05-19

Who should care

Organizations using Microsoft Office 2024 LTSC, Office LTSC 2021, or OneNote on macOS; security teams managing macOS endpoint protection; users who exchange OneNote documents externally

Technical summary

This vulnerability in Microsoft OneNote for macOS permits remote code execution when a user opens a specially crafted OneNote document. The attack requires local access context (AV:L) but no privileges, with successful exploitation yielding high impact to confidentiality, integrity, and availability. The underlying weakness relates to improper handling of file or resource names (CWE-641).

Defensive priority

HIGH

Recommended defensive actions

  • Apply Microsoft security updates for Office 2024 LTSC, Office LTSC 2021, and OneNote for macOS as referenced in the Microsoft Security Response Center advisory
  • Educate users to avoid opening OneNote files from untrusted sources
  • Consider application control policies to restrict execution of untrusted Office documents on macOS endpoints
  • Monitor for suspicious OneNote-related process execution on macOS systems

Evidence notes

CVE published 2025-01-14; modified 2026-05-19. CVSS 3.1 vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. Affected CPEs confirm macOS-specific Office and OneNote versions. Microsoft tags reference as 'Patch, Vendor Advisory'.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-21402 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-21402

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-21402 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-21402

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.