CVE-2025-21360: Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability

Overview

Severity
High (CVSS 7.8)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2025-Jan
Released
2025-01-14
Last Updated
2025-01-30
EPSS Score
0.22% (percentile: 44.4%)

FAQ

What privileges could be gained by an attacker who successfully exploited the vulnerability? An attacker who successfully exploits this vulnerability could elevate their privileges to perform commands as Root in the target environment.

Affected Products (1)

Microsoft Office

  • Microsoft AutoUpdate for Mac

Security Updates (1)

Acknowledgments

Anonymous

Revision History

  • 2025-01-14: Information published.
  • 2025-01-30: Updated one or more CVSS scores for the affected products. This is an informational change only.