CVE-2025-55243: Microsoft Officeplus

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to perform spoofing over a network.

Affected products

  • Microsoft Officeplus: before 3.10.0.26585 (fixed in 3.10.0.26585)

Published 2025-09-09. Last modified 2026-06-17.