{
    "document": {
        "category": "csaf_security_advisory",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "nl",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this page to enhance access to its information and security advisories. The use of this security advisory is subject to the following terms and conditions:\n\n    NCSC-NL makes every reasonable effort to ensure that the content of this page is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or continuous keeping up-to-date. The information contained in this security advisory is intended solely for the purpose of providing general information to professional users. No rights can be derived from the information provided therein.\n\n    NCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of this security advisory. This includes damage resulting from the inaccuracy of incompleteness of the information contained in the advisory.\n    This security advisory is subject to Dutch law. All disputes related to or arising from the use of this advisory will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            },
            {
                "category": "description",
                "text": "Microsoft heeft kwetsbaarheden verholpen in diverse Office producten.",
                "title": "Feiten"
            },
            {
                "category": "description",
                "text": "Een kwaadwillende kan de kwetsbaarheden misbruiken om een beveiligingsmaatregel te omzeilen, zich voor te doen als andere gebruiker, toegang te krijgen tot gevoelige gegevens of willekeurige code uit te voeren in de context van het slachtoffer.\n\nVoor succesvol misbruik moet de kwaadwillende het slachtoffer misleiden een malafide bestand te openen of link te volgen.\n\n```\nMicrosoft Purview: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2025-21385 | 8.80 | Toegang tot gevoelige gegevens      | \n|----------------|------|-------------------------------------|\n\nMicrosoft Office Word: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2025-21363 | 7.80 | Uitvoeren van willekeurige code     | \n|----------------|------|-------------------------------------|\n\nWindows Win32K - GRFX: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2025-21338 | 7.80 | Uitvoeren van willekeurige code     | \n|----------------|------|-------------------------------------|\n\nMicrosoft Office: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2025-21346 | 7.10 | Omzeilen van beveiligingsmaatregel  | \n| CVE-2025-21365 | 7.80 | Uitvoeren van willekeurige code     | \n|----------------|------|-------------------------------------|\n\nMicrosoft Office Excel: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2025-21354 | 7.80 | Uitvoeren van willekeurige code     | \n| CVE-2025-21362 | 7.80 | Uitvoeren van willekeurige code     | \n| CVE-2025-21364 | 7.80 | Omzeilen van beveiligingsmaatregel  | \n|----------------|------|-------------------------------------|\n\nMicrosoft Office Outlook: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2025-21357 | 6.70 | Uitvoeren van willekeurige code     | \n|----------------|------|-------------------------------------|\n\nMicrosoft AutoUpdate (MAU): \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2025-21360 | 7.80 | Verkrijgen van verhoogde rechten    | \n|----------------|------|-------------------------------------|\n\nMicrosoft Office Outlook for Mac: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2025-21361 | 7.80 | Uitvoeren van willekeurige code     | \n|----------------|------|-------------------------------------|\n\nMicrosoft Office Visio: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2025-21345 | 7.80 | Uitvoeren van willekeurige code     | \n| CVE-2025-21356 | 7.80 | Uitvoeren van willekeurige code     | \n|----------------|------|-------------------------------------|\n\nMicrosoft Office Access: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2025-21366 | 7.80 | Uitvoeren van willekeurige code     | \n| CVE-2025-21395 | 7.80 | Uitvoeren van willekeurige code     | \n| CVE-2025-21186 | 7.80 | Uitvoeren van willekeurige code     | \n|----------------|------|-------------------------------------|\n\nMicrosoft Office OneNote: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2025-21402 | 7.80 | Uitvoeren van willekeurige code     | \n|----------------|------|-------------------------------------|\n\nMicrosoft Office SharePoint: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2025-21344 | 7.80 | Uitvoeren van willekeurige code     | \n| CVE-2025-21348 | 7.20 | Uitvoeren van willekeurige code     | \n| CVE-2025-21393 | 6.30 | Voordoen als andere gebruiker       | \n|----------------|------|-------------------------------------|\n\n```",
                "title": "Interpretaties"
            },
            {
                "category": "description",
                "text": "Microsoft heeft updates beschikbaar gesteld waarmee de beschreven kwetsbaarheden worden verholpen. We raden u aan om deze updates te installeren. Meer informatie over de kwetsbaarheden, de installatie van de updates en eventuele work-arounds vindt u op:\n\nhttps://portal.msrc.microsoft.com/en-us/security-guidance",
                "title": "Oplossingen"
            },
            {
                "category": "general",
                "text": "medium",
                "title": "Kans"
            },
            {
                "category": "general",
                "text": "high",
                "title": "Schade"
            },
            {
                "category": "general",
                "text": "Improper Restriction of Names for Files and Other Resources",
                "title": "CWE-641"
            },
            {
                "category": "general",
                "text": "Untrusted Pointer Dereference",
                "title": "CWE-822"
            },
            {
                "category": "general",
                "text": "Use of Uninitialized Resource",
                "title": "CWE-908"
            },
            {
                "category": "general",
                "text": "Untrusted Search Path",
                "title": "CWE-426"
            },
            {
                "category": "general",
                "text": "Access of Resource Using Incompatible Type ('Type Confusion')",
                "title": "CWE-843"
            },
            {
                "category": "general",
                "text": "Integer Overflow or Wraparound",
                "title": "CWE-190"
            },
            {
                "category": "general",
                "text": "Protection Mechanism Failure",
                "title": "CWE-693"
            },
            {
                "category": "general",
                "text": "Improper Authorization",
                "title": "CWE-285"
            },
            {
                "category": "general",
                "text": "Use After Free",
                "title": "CWE-416"
            },
            {
                "category": "general",
                "text": "Deserialization of Untrusted Data",
                "title": "CWE-502"
            },
            {
                "category": "general",
                "text": "Heap-based Buffer Overflow",
                "title": "CWE-122"
            },
            {
                "category": "general",
                "text": "Improper Privilege Management",
                "title": "CWE-269"
            },
            {
                "category": "general",
                "text": "Improper Input Validation",
                "title": "CWE-20"
            },
            {
                "category": "general",
                "text": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
                "title": "CWE-79"
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "Nationaal Cyber Security Centrum",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "Kwetsbaarheden verholpen in Microsoft Office",
        "tracking": {
            "current_release_date": "2025-01-14T19:15:33.729625Z",
            "id": "NCSC-2025-0012",
            "initial_release_date": "2025-01-14T19:15:33.729625Z",
            "revision_history": [
                {
                    "date": "2025-01-14T19:15:33.729625Z",
                    "number": "0",
                    "summary": "Initiele versie"
                }
            ],
            "status": "final",
            "version": "1.0.0"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "category": "product_name",
                        "name": "microsoft_365_apps_for_enterprise",
                        "product": {
                            "name": "microsoft_365_apps_for_enterprise",
                            "product_id": "CSAFPID-1741358",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_365_apps_for_enterprise:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_access_2016",
                        "product": {
                            "name": "microsoft_access_2016",
                            "product_id": "CSAFPID-1749640",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_access_2016:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_access_2016__32-bit_edition_",
                        "product": {
                            "name": "microsoft_access_2016__32-bit_edition_",
                            "product_id": "CSAFPID-1718417",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_access_2016__32-bit_edition_:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_autoupdate_for_mac",
                        "product": {
                            "name": "microsoft_autoupdate_for_mac",
                            "product_id": "CSAFPID-1719189",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_autoupdate_for_mac:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_excel_2016",
                        "product": {
                            "name": "microsoft_excel_2016",
                            "product_id": "CSAFPID-1741364",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_excel_2016:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_office_2016",
                        "product": {
                            "name": "microsoft_office_2016",
                            "product_id": "CSAFPID-1741376",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_office_2016:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_office_2019",
                        "product": {
                            "name": "microsoft_office_2019",
                            "product_id": "CSAFPID-1741357",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_office_2019:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_office_for_android",
                        "product": {
                            "name": "microsoft_office_for_android",
                            "product_id": "CSAFPID-1741500",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_office_for_android:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_office_for_ios",
                        "product": {
                            "name": "microsoft_office_for_ios",
                            "product_id": "CSAFPID-1747210",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_office_for_ios:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_office_for_mac",
                        "product": {
                            "name": "microsoft_office_for_mac",
                            "product_id": "CSAFPID-1749646",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_office_for_mac:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_office_for_universal",
                        "product": {
                            "name": "microsoft_office_for_universal",
                            "product_id": "CSAFPID-1741501",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_office_for_universal:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_office_ltsc_2021",
                        "product": {
                            "name": "microsoft_office_ltsc_2021",
                            "product_id": "CSAFPID-1741359",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_office_ltsc_2021:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_office_ltsc_2024",
                        "product": {
                            "name": "microsoft_office_ltsc_2024",
                            "product_id": "CSAFPID-1741360",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_office_ltsc_2024:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_office_ltsc_for_mac_2021",
                        "product": {
                            "name": "microsoft_office_ltsc_for_mac_2021",
                            "product_id": "CSAFPID-1717981",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_office_ltsc_for_mac_2021:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_office_ltsc_for_mac_2024",
                        "product": {
                            "name": "microsoft_office_ltsc_for_mac_2024",
                            "product_id": "CSAFPID-1741363",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_office_ltsc_for_mac_2024:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_onenote",
                        "product": {
                            "name": "microsoft_onenote",
                            "product_id": "CSAFPID-1749643",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_onenote:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_outlook_2016",
                        "product": {
                            "name": "microsoft_outlook_2016",
                            "product_id": "CSAFPID-1741534",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_outlook_2016:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_outlook_for_mac",
                        "product": {
                            "name": "microsoft_outlook_for_mac",
                            "product_id": "CSAFPID-1749645",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_outlook_for_mac:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_purview",
                        "product": {
                            "name": "microsoft_purview",
                            "product_id": "CSAFPID-1748814",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_purview:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_sharepoint_enterprise_server_2016",
                        "product": {
                            "name": "microsoft_sharepoint_enterprise_server_2016",
                            "product_id": "CSAFPID-1717940",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_sharepoint_enterprise_server_2016:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_sharepoint_server_2019",
                        "product": {
                            "name": "microsoft_sharepoint_server_2019",
                            "product_id": "CSAFPID-1717942",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_sharepoint_server_2019:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_sharepoint_server_subscription_edition",
                        "product": {
                            "name": "microsoft_sharepoint_server_subscription_edition",
                            "product_id": "CSAFPID-1717943",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_sharepoint_server_subscription_edition:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "office_online_server",
                        "product": {
                            "name": "office_online_server",
                            "product_id": "CSAFPID-510412",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:office_online_server:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "office_purview",
                        "product": {
                            "name": "office_purview",
                            "product_id": "CSAFPID-1748844",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:office_purview:*:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "purview",
                        "product": {
                            "name": "purview",
                            "product_id": "CSAFPID-1748958",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:purview:-:*:*:*:*:*:*:*"
                            }
                        }
                    }
                ],
                "category": "vendor",
                "name": "microsoft"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2025-21186",
            "cwe": {
                "id": "CWE-122",
                "name": "Heap-based Buffer Overflow"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Heap-based Buffer Overflow",
                    "title": "CWE-122"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1741357",
                    "CSAFPID-1741358",
                    "CSAFPID-1741359",
                    "CSAFPID-1741360",
                    "CSAFPID-1718417",
                    "CSAFPID-1749640"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2025-21186",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2025/CVE-2025-21186.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1741357",
                        "CSAFPID-1741358",
                        "CSAFPID-1741359",
                        "CSAFPID-1741360",
                        "CSAFPID-1718417",
                        "CSAFPID-1749640"
                    ]
                }
            ],
            "title": "CVE-2025-21186"
        },
        {
            "cve": "CVE-2025-21338",
            "cwe": {
                "id": "CWE-190",
                "name": "Integer Overflow or Wraparound"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Integer Overflow or Wraparound",
                    "title": "CWE-190"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1749646",
                    "CSAFPID-1717981",
                    "CSAFPID-1747210",
                    "CSAFPID-1741500",
                    "CSAFPID-1741501",
                    "CSAFPID-1741363"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2025-21338",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2025/CVE-2025-21338.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1749646",
                        "CSAFPID-1717981",
                        "CSAFPID-1747210",
                        "CSAFPID-1741500",
                        "CSAFPID-1741501",
                        "CSAFPID-1741363"
                    ]
                }
            ],
            "title": "CVE-2025-21338"
        },
        {
            "cve": "CVE-2025-21344",
            "cwe": {
                "id": "CWE-20",
                "name": "Improper Input Validation"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Improper Input Validation",
                    "title": "CWE-20"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1717940",
                    "CSAFPID-1717942",
                    "CSAFPID-1717943"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2025-21344",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2025/CVE-2025-21344.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1717940",
                        "CSAFPID-1717942",
                        "CSAFPID-1717943"
                    ]
                }
            ],
            "title": "CVE-2025-21344"
        },
        {
            "cve": "CVE-2025-21345",
            "cwe": {
                "id": "CWE-416",
                "name": "Use After Free"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Use After Free",
                    "title": "CWE-416"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1741357",
                    "CSAFPID-1741358",
                    "CSAFPID-1741359",
                    "CSAFPID-1741360"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2025-21345",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2025/CVE-2025-21345.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1741357",
                        "CSAFPID-1741358",
                        "CSAFPID-1741359",
                        "CSAFPID-1741360"
                    ]
                }
            ],
            "title": "CVE-2025-21345"
        },
        {
            "cve": "CVE-2025-21346",
            "cwe": {
                "id": "CWE-693",
                "name": "Protection Mechanism Failure"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Protection Mechanism Failure",
                    "title": "CWE-693"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1741357",
                    "CSAFPID-1741358",
                    "CSAFPID-1741359",
                    "CSAFPID-1741360",
                    "CSAFPID-1741376"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2025-21346",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2025/CVE-2025-21346.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1741357",
                        "CSAFPID-1741358",
                        "CSAFPID-1741359",
                        "CSAFPID-1741360",
                        "CSAFPID-1741376"
                    ]
                }
            ],
            "title": "CVE-2025-21346"
        },
        {
            "cve": "CVE-2025-21348",
            "cwe": {
                "id": "CWE-285",
                "name": "Improper Authorization"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Improper Authorization",
                    "title": "CWE-285"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1717940",
                    "CSAFPID-1717942",
                    "CSAFPID-1717943"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2025-21348",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2025/CVE-2025-21348.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1717940",
                        "CSAFPID-1717942",
                        "CSAFPID-1717943"
                    ]
                }
            ],
            "title": "CVE-2025-21348"
        },
        {
            "cve": "CVE-2025-21354",
            "cwe": {
                "id": "CWE-822",
                "name": "Untrusted Pointer Dereference"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Untrusted Pointer Dereference",
                    "title": "CWE-822"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-510412",
                    "CSAFPID-1741357",
                    "CSAFPID-1741358",
                    "CSAFPID-1717981",
                    "CSAFPID-1741359",
                    "CSAFPID-1741360",
                    "CSAFPID-1741363"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2025-21354",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2025/CVE-2025-21354.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-510412",
                        "CSAFPID-1741357",
                        "CSAFPID-1741358",
                        "CSAFPID-1717981",
                        "CSAFPID-1741359",
                        "CSAFPID-1741360",
                        "CSAFPID-1741363"
                    ]
                }
            ],
            "title": "CVE-2025-21354"
        },
        {
            "cve": "CVE-2025-21356",
            "cwe": {
                "id": "CWE-843",
                "name": "Access of Resource Using Incompatible Type ('Type Confusion')"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Access of Resource Using Incompatible Type ('Type Confusion')",
                    "title": "CWE-843"
                },
                {
                    "category": "other",
                    "text": "Heap-based Buffer Overflow",
                    "title": "CWE-122"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1741357",
                    "CSAFPID-1741358",
                    "CSAFPID-1741359",
                    "CSAFPID-1741360"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2025-21356",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2025/CVE-2025-21356.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1741357",
                        "CSAFPID-1741358",
                        "CSAFPID-1741359",
                        "CSAFPID-1741360"
                    ]
                }
            ],
            "title": "CVE-2025-21356"
        },
        {
            "cve": "CVE-2025-21357",
            "cwe": {
                "id": "CWE-908",
                "name": "Use of Uninitialized Resource"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Use of Uninitialized Resource",
                    "title": "CWE-908"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1741357",
                    "CSAFPID-1741358",
                    "CSAFPID-1741359",
                    "CSAFPID-1741360",
                    "CSAFPID-1741534"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2025-21357",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2025/CVE-2025-21357.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 6.7,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1741357",
                        "CSAFPID-1741358",
                        "CSAFPID-1741359",
                        "CSAFPID-1741360",
                        "CSAFPID-1741534"
                    ]
                }
            ],
            "title": "CVE-2025-21357"
        },
        {
            "cve": "CVE-2025-21360",
            "cwe": {
                "id": "CWE-269",
                "name": "Improper Privilege Management"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Improper Privilege Management",
                    "title": "CWE-269"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1719189"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2025-21360",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2025/CVE-2025-21360.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1719189"
                    ]
                }
            ],
            "title": "CVE-2025-21360"
        },
        {
            "cve": "CVE-2025-21361",
            "cwe": {
                "id": "CWE-641",
                "name": "Improper Restriction of Names for Files and Other Resources"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Improper Restriction of Names for Files and Other Resources",
                    "title": "CWE-641"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1717981",
                    "CSAFPID-1749645",
                    "CSAFPID-1741363"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2025-21361",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2025/CVE-2025-21361.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1717981",
                        "CSAFPID-1749645",
                        "CSAFPID-1741363"
                    ]
                }
            ],
            "title": "CVE-2025-21361"
        },
        {
            "cve": "CVE-2025-21362",
            "cwe": {
                "id": "CWE-416",
                "name": "Use After Free"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Use After Free",
                    "title": "CWE-416"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-510412",
                    "CSAFPID-1741357",
                    "CSAFPID-1741358",
                    "CSAFPID-1717981",
                    "CSAFPID-1741359",
                    "CSAFPID-1741360",
                    "CSAFPID-1741363",
                    "CSAFPID-1741364"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2025-21362",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2025/CVE-2025-21362.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-510412",
                        "CSAFPID-1741357",
                        "CSAFPID-1741358",
                        "CSAFPID-1717981",
                        "CSAFPID-1741359",
                        "CSAFPID-1741360",
                        "CSAFPID-1741363",
                        "CSAFPID-1741364"
                    ]
                }
            ],
            "title": "CVE-2025-21362"
        },
        {
            "cve": "CVE-2025-21363",
            "cwe": {
                "id": "CWE-822",
                "name": "Untrusted Pointer Dereference"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Untrusted Pointer Dereference",
                    "title": "CWE-822"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1741358",
                    "CSAFPID-1717981",
                    "CSAFPID-1741360",
                    "CSAFPID-1741363"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2025-21363",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2025/CVE-2025-21363.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1741358",
                        "CSAFPID-1717981",
                        "CSAFPID-1741360",
                        "CSAFPID-1741363"
                    ]
                }
            ],
            "title": "CVE-2025-21363"
        },
        {
            "cve": "CVE-2025-21364",
            "cwe": {
                "id": "CWE-502",
                "name": "Deserialization of Untrusted Data"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Deserialization of Untrusted Data",
                    "title": "CWE-502"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1741358",
                    "CSAFPID-1741360"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2025-21364",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2025/CVE-2025-21364.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1741358",
                        "CSAFPID-1741360"
                    ]
                }
            ],
            "title": "CVE-2025-21364"
        },
        {
            "cve": "CVE-2025-21365",
            "cwe": {
                "id": "CWE-426",
                "name": "Untrusted Search Path"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Untrusted Search Path",
                    "title": "CWE-426"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1741358",
                    "CSAFPID-1741360"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2025-21365",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2025/CVE-2025-21365.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1741358",
                        "CSAFPID-1741360"
                    ]
                }
            ],
            "title": "CVE-2025-21365"
        },
        {
            "cve": "CVE-2025-21366",
            "cwe": {
                "id": "CWE-416",
                "name": "Use After Free"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Use After Free",
                    "title": "CWE-416"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1741357",
                    "CSAFPID-1741358",
                    "CSAFPID-1741359",
                    "CSAFPID-1741360",
                    "CSAFPID-1718417",
                    "CSAFPID-1749640"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2025-21366",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2025/CVE-2025-21366.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1741357",
                        "CSAFPID-1741358",
                        "CSAFPID-1741359",
                        "CSAFPID-1741360",
                        "CSAFPID-1718417",
                        "CSAFPID-1749640"
                    ]
                }
            ],
            "title": "CVE-2025-21366"
        },
        {
            "cve": "CVE-2025-21385",
            "cwe": {
                "id": "CWE-918",
                "name": "Server-Side Request Forgery (SSRF)"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Server-Side Request Forgery (SSRF)",
                    "title": "CWE-918"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1748814",
                    "CSAFPID-1748844"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2025-21385",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2025/CVE-2025-21385.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1748814",
                        "CSAFPID-1748844"
                    ]
                }
            ],
            "title": "CVE-2025-21385"
        },
        {
            "cve": "CVE-2025-21393",
            "cwe": {
                "id": "CWE-79",
                "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
                    "title": "CWE-79"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1717940",
                    "CSAFPID-1717942",
                    "CSAFPID-1717943"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2025-21393",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2025/CVE-2025-21393.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C",
                        "baseScore": 6.3,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1717940",
                        "CSAFPID-1717942",
                        "CSAFPID-1717943"
                    ]
                }
            ],
            "title": "CVE-2025-21393"
        },
        {
            "cve": "CVE-2025-21395",
            "cwe": {
                "id": "CWE-122",
                "name": "Heap-based Buffer Overflow"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Heap-based Buffer Overflow",
                    "title": "CWE-122"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1741357",
                    "CSAFPID-1741358",
                    "CSAFPID-1741359",
                    "CSAFPID-1741360",
                    "CSAFPID-1718417",
                    "CSAFPID-1749640"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2025-21395",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2025/CVE-2025-21395.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1741357",
                        "CSAFPID-1741358",
                        "CSAFPID-1741359",
                        "CSAFPID-1741360",
                        "CSAFPID-1718417",
                        "CSAFPID-1749640"
                    ]
                }
            ],
            "title": "CVE-2025-21395"
        },
        {
            "cve": "CVE-2025-21402",
            "cwe": {
                "id": "CWE-641",
                "name": "Improper Restriction of Names for Files and Other Resources"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Improper Restriction of Names for Files and Other Resources",
                    "title": "CWE-641"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1717981",
                    "CSAFPID-1741363",
                    "CSAFPID-1749643"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2025-21402",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2025/CVE-2025-21402.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1717981",
                        "CSAFPID-1741363",
                        "CSAFPID-1749643"
                    ]
                }
            ],
            "title": "CVE-2025-21402"
        }
    ]
}