Skip to main content

Improper Restriction of Names for Files and Other Resources

CVE-2025-21402

Severity High
Score 7.8/10

Summary

Microsoft Office OneNote Remote Code Execution Vulnerability

  • LOW
  • LOCAL
  • HIGH
  • UNCHANGED
  • REQUIRED
  • NONE
  • HIGH
  • HIGH

CWE-641 - Improper Restriction of Names for Files and Other Resources

The application constructs the name of a file or other resource using input from an upstream component, but it does not restrict or incorrectly restricts the resulting name.

References

Advisory Timeline

  • Published