CVE-2025-55322

7.3

Microsoft · OmniParser

A vulnerability in Microsoft OmniParser allows unauthenticated remote attackers to execute code due to binding to an unrestricted IP address.

Executive summary

A critical vulnerability in Microsoft OmniParser allows an unauthenticated remote attacker to execute arbitrary code by exploiting an insecure network binding configuration.

Vulnerability

The software binds to an unrestricted IP address, which enables an unauthenticated attacker to interact with the service over a network to achieve remote code execution.

Business impact

This vulnerability carries a CVSS score of 7.3, categorizing it as a High severity issue. Successful exploitation allows an attacker to bypass authentication controls and execute arbitrary code, potentially leading to full system compromise, unauthorized data access, and significant operational disruption.

Remediation

Immediate Action: Update Microsoft OmniParser to version 2.0.1 or later as specified in the official Microsoft security update guide.

Proactive Monitoring: Monitor network traffic for unusual connection patterns to the OmniParser service and audit system logs for unauthorized execution attempts or unexpected process spawning.

Compensating Controls: Deploy a firewall or network access control list (ACL) to restrict access to the service to authorized IP addresses only until the patch can be applied.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The risk posed by this vulnerability is significant due to the lack of required authentication for exploitation. Security teams should prioritize patching Microsoft OmniParser to version 2.0.1 immediately to eliminate the exposure, as the current network binding configuration provides an accessible attack surface for remote adversaries.

More Microsoft CVEs

Sources