
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62560 is an untrusted pointer dereference vulnerability in Microsoft Office Excel that allows an unauthorized local attacker to execute arbitrary code on a victim's system. It was disclosed on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday security update cycle. Affected products include Microsoft Excel 2016, Microsoft 365 Apps for Enterprise, Office 2019, Office 2021, Office 2024, Office LTSC 2021/2024 (Windows and macOS), and Office Online Server (versions prior to 16.0.10417.20075). The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).
The root cause is classified under CWE-822 (Untrusted Pointer Dereference) and CWE-126 (Buffer Over-read), mapped to CAPEC-129 (Pointer Manipulation). An attacker crafts a malicious Excel file that, when opened by a victim, causes Excel to dereference an untrusted pointer — reading from or writing to an attacker-controlled memory address — which can lead to arbitrary code execution in the context of the current user. Exploitation requires local access and user interaction (opening a malicious file), with no privileges required on the part of the attacker (Microsoft MSRC, Feedly). No public proof-of-concept code has been identified at this time.
Successful exploitation grants an attacker the ability to execute arbitrary code with the privileges of the logged-in user, potentially resulting in complete system compromise, unauthorized access to sensitive data, and installation of malware. The confidentiality, integrity, and availability impacts are all rated High, meaning an attacker could read, modify, or destroy data and disrupt system operation. If the victim has elevated privileges, the impact is amplified, and the attacker may use the compromised system as a foothold for lateral movement within the network (Microsoft MSRC, Feedly).
%TEMP%, %APPDATA%) following the opening of an Excel file; suspicious Excel files received via email or downloaded from unknown sources.EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe); Excel process making unexpected outbound network connections.EXCEL.EXE to unknown or suspicious IP addresses or domains; DNS queries for unusual domains initiated shortly after opening an Excel file.EXCEL.EXE as the parent process for unexpected child processes; application crash logs or Dr. Watson/WER reports referencing Excel memory access violations.Microsoft released patches for CVE-2025-62560 on December 9, 2025, as part of the December 2025 Patch Tuesday update. Organizations should apply the relevant security updates immediately: Excel 2016 should be updated to build 16.0.5530.1000 or later, and Office Online Server to version 16.0.10417.20075 or later; Microsoft 365 Apps, Office 2019, 2021, and 2024 should be updated via the Microsoft Office Security Releases page. As interim mitigations, organizations should enable Protected View for files from untrusted sources, restrict users from opening Excel files from unknown senders, implement email filtering to block suspicious attachments, and ensure endpoint protection solutions are up to date (Microsoft MSRC, Feedly).
The vulnerability was covered as part of broader December 2025 Patch Tuesday roundups by multiple security outlets. BleepingComputer noted the December 2025 update addressed 57 flaws including 3 zero-days, with CVE-2025-62560 among the Excel-specific issues (BleepingComputer). The Zero Day Initiative reviewed the December 2025 security updates and highlighted the Excel vulnerabilities (ZDI). Sophos and Rapid7 also published Patch Tuesday analyses covering this CVE as part of the broader update batch (Sophos, Rapid7). No significant independent researcher commentary or social media controversy specific to this CVE was identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."