CVE-2025-62560
vulnerability analysis and mitigation

Overview

CVE-2025-62560 is an untrusted pointer dereference vulnerability in Microsoft Office Excel that allows an unauthorized local attacker to execute arbitrary code on a victim's system. It was disclosed on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday security update cycle. Affected products include Microsoft Excel 2016, Microsoft 365 Apps for Enterprise, Office 2019, Office 2021, Office 2024, Office LTSC 2021/2024 (Windows and macOS), and Office Online Server (versions prior to 16.0.10417.20075). The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).

Technical details

The root cause is classified under CWE-822 (Untrusted Pointer Dereference) and CWE-126 (Buffer Over-read), mapped to CAPEC-129 (Pointer Manipulation). An attacker crafts a malicious Excel file that, when opened by a victim, causes Excel to dereference an untrusted pointer — reading from or writing to an attacker-controlled memory address — which can lead to arbitrary code execution in the context of the current user. Exploitation requires local access and user interaction (opening a malicious file), with no privileges required on the part of the attacker (Microsoft MSRC, Feedly). No public proof-of-concept code has been identified at this time.

Impact

Successful exploitation grants an attacker the ability to execute arbitrary code with the privileges of the logged-in user, potentially resulting in complete system compromise, unauthorized access to sensitive data, and installation of malware. The confidentiality, integrity, and availability impacts are all rated High, meaning an attacker could read, modify, or destroy data and disrupt system operation. If the victim has elevated privileges, the impact is amplified, and the attacker may use the compromised system as a foothold for lateral movement within the network (Microsoft MSRC, Feedly).

Exploitation steps

  1. Craft malicious Excel file: An attacker creates a specially crafted Excel file (.xlsx, .xls, or similar) that contains data designed to trigger an untrusted pointer dereference when parsed by the Excel application.
  2. Deliver the file: The attacker delivers the malicious file to the target via phishing email, malicious download link, or shared network drive, relying on social engineering to convince the victim to open it.
  3. Victim opens the file: The victim opens the malicious Excel file using a vulnerable version of Microsoft Excel (e.g., Excel 2016, Microsoft 365 Apps).
  4. Trigger pointer dereference: Excel processes the malformed file content, causing it to dereference an attacker-controlled pointer value, leading to a buffer over-read or memory corruption condition.
  5. Achieve code execution: The memory corruption is leveraged to redirect execution flow, allowing the attacker to execute arbitrary shellcode or commands in the context of the victim's user account, potentially enabling persistence, data exfiltration, or further lateral movement (Microsoft MSRC, Feedly).

Indicators of compromise

  • File System: Unexpected or newly created executable files, scripts, or DLLs in user temp directories (e.g., %TEMP%, %APPDATA%) following the opening of an Excel file; suspicious Excel files received via email or downloaded from unknown sources.
  • Process: Unusual child processes spawned by EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe); Excel process making unexpected outbound network connections.
  • Network: Outbound connections from EXCEL.EXE to unknown or suspicious IP addresses or domains; DNS queries for unusual domains initiated shortly after opening an Excel file.
  • Logs: Windows Event Log entries (Event ID 4688) showing process creation with EXCEL.EXE as the parent process for unexpected child processes; application crash logs or Dr. Watson/WER reports referencing Excel memory access violations.

Mitigation and workarounds

Microsoft released patches for CVE-2025-62560 on December 9, 2025, as part of the December 2025 Patch Tuesday update. Organizations should apply the relevant security updates immediately: Excel 2016 should be updated to build 16.0.5530.1000 or later, and Office Online Server to version 16.0.10417.20075 or later; Microsoft 365 Apps, Office 2019, 2021, and 2024 should be updated via the Microsoft Office Security Releases page. As interim mitigations, organizations should enable Protected View for files from untrusted sources, restrict users from opening Excel files from unknown senders, implement email filtering to block suspicious attachments, and ensure endpoint protection solutions are up to date (Microsoft MSRC, Feedly).

Community reactions

The vulnerability was covered as part of broader December 2025 Patch Tuesday roundups by multiple security outlets. BleepingComputer noted the December 2025 update addressed 57 flaws including 3 zero-days, with CVE-2025-62560 among the Excel-specific issues (BleepingComputer). The Zero Day Initiative reviewed the December 2025 security updates and highlighted the Excel vulnerabilities (ZDI). Sophos and Rapid7 also published Patch Tuesday analyses covering this CVE as part of the broader update batch (Sophos, Rapid7). No significant independent researcher commentary or social media controversy specific to this CVE was identified.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management