VDB

GCVE-110-NCSC-2025-215

GCVE-110-NCSC-2025-215
Advisory PublishedCVSS 5.5/10
Vulnetix · Advisory published July 8, 2025
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Weaknesses (CWE)

CWE-502Deserialization of Untrusted DataCWE-125Out-of-bounds ReadCWE-416Use After FreeCWE-122Heap-based Buffer OverflowCWE-843Access of Resource Using Incompatible Type ('Type Confusion')CWE-280Improper Handling of Insufficient Permissions or PrivilegesCWE-285Improper AuthorizationCWE-94Improper Control of Generation of Code ('Code Injection')CWE-287Improper AuthenticationCWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Risk Scores

CVSS 3.1
5.5/10
Medium · CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersionsPlatforms
Microsoftvers:unknown/16.0.1|<16.0.5508.1000
Microsoftvers:unknown/2.0.0|<7.10.1(100772025102901)
Microsoftvers:unknown/16.0.1|<16.0.19029.20000
Microsoftvers:unknown/1.0.0|<25060212643
Microsoftvers:unknown/19.0.0|<https://aka.ms/officesecurityreleases
Microsoftvers:unknown/16.0.0.0|<16.0.5508.1002
Microsoftvers:unknown/16.0.0|<16.0.5508.1000
Microsoftvers:unknown/16.0.0|<16.0.18526.20424
Microsoftvers:unknown/1.0.0.0|<25163.3001.3726.6503
Microsoftvers:unknown/1.0.0|<https://aka.ms/officesecurityreleases
Microsoftvers:unknown/16.0.1|<16.0.5508.1001
Microsoftvers:unknown/n/a
Microsoftvers:unknown/16.0.0.0|<16.0.5508.1001
Microsoftvers:unknown/1.0.0|<1.0.0.2025112902
Microsoftvers:unknown/1.0.0|<16.0.10417.20027
Microsoftvers:unknown/16.0.0|<16.0.5508.1001
Microsoftvers:unknown/16.0.0|<16.0.10417.20027
Microsoftvers:unknown/16.0.1|<https://aka.ms/officesecurityreleases

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

75,874 records in the GCVE database · Updated August 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›