AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-14714

MEDIUM · CVSS 6.5 EPSS 0.13%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-12-15 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.5. It affects Office.

CVE
CVE-2025-14714
Severity
MEDIUM
CVSS
6.5
EPSS
0.13%
Office

Original NVD Description

An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle By executing the bundled interpreter directly the attacker's scripts run with the application's TCC privileges In fixed versions parent-constraints are used to allow only the main application to launch interpreter with those permissions This issue affects LibreOffice on macOS: from 25.2 before < 25.2.4.

Related CVEs

Other vulnerabilities affecting the same vendor(s)