
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62561 is an untrusted pointer dereference vulnerability in Microsoft Office Excel that allows an unauthorized attacker to execute arbitrary code locally. It was disclosed and patched on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday security update. Affected products include Microsoft Excel 2016, Office 2019, Office 2021 (LTSC), Office 2024 (LTSC), Microsoft 365 Apps for Enterprise, Office Online Server (versions prior to 16.0.10417.20075), and their macOS counterparts. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).
The root cause is classified as CWE-822 (Untrusted Pointer Dereference), where Excel fails to properly validate pointer values derived from attacker-controlled data in a malicious file, leading to memory corruption. The attack vector is local, requiring low attack complexity and no special privileges, but does require user interaction — specifically, a victim must open a specially crafted Excel document. The exploitation mechanism aligns with CAPEC-129 (Pointer Manipulation), where a malformed file causes Excel to dereference an attacker-controlled memory address, potentially redirecting execution flow. No public proof-of-concept code has been identified at this time (Microsoft MSRC, Feedly).
Successful exploitation results in high confidentiality, integrity, and availability impact on the affected system, enabling an attacker to execute arbitrary code in the context of the logged-in user. If the victim has administrative privileges, the attacker could achieve full system compromise, including data theft, installation of malware, or lateral movement within the network. The scope is limited to the affected system (unchanged scope), but the combination of code execution and high-impact triad makes this a significant risk for enterprise environments relying on Microsoft Office (Microsoft MSRC, Feedly).
.xlsx or .xls file containing malformed data structures designed to supply an untrusted pointer value during Excel's file parsing routines.%TEMP%, %APPDATA%) following the opening of an Excel document; suspicious .xlsx/.xls files received via email or downloaded from untrusted sources.EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe); Excel process making unexpected outbound network connections.EXCEL.EXE to unknown or suspicious IP addresses or domains shortly after a file is opened.EXCEL.EXE; security logs recording new process creation events with EXCEL.EXE as the parent process.Microsoft released patches on December 9, 2025, as part of the December 2025 Patch Tuesday update. Specific fixed versions include Microsoft Excel 2016 (build 16.0.5530.1000 and later) and Office Online Server (build 16.0.10417.20075 and later); all other affected products should be updated via Microsoft Update or the Office Deployment Tool to the latest available build (Microsoft MSRC). As interim mitigations, organizations should disable macros, implement email filtering to block unsolicited Office file attachments, and train users to avoid opening Excel files from untrusted sources. Enabling Microsoft Defender's Attack Surface Reduction (ASR) rules to block Office applications from creating child processes can also reduce exploitation risk (Feedly).
The vulnerability was covered as part of broader December 2025 Patch Tuesday roundups by multiple security outlets. Bleeping Computer noted the December 2025 update addressed 57 flaws including 3 zero-days, with CVE-2025-62561 among the Excel-specific issues (BleepingComputer). Zero Day Initiative (ZDI) included it in their December 2025 security update review (ZDI Blog). Sophos and Rapid7 also published Patch Tuesday analyses covering this vulnerability, with no specific researcher commentary singling it out as particularly novel or immediately dangerous given the absence of a public PoC (Sophos, Rapid7).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."