CVE-2025-62561
vulnerability analysis and mitigation

Overview

CVE-2025-62561 is an untrusted pointer dereference vulnerability in Microsoft Office Excel that allows an unauthorized attacker to execute arbitrary code locally. It was disclosed and patched on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday security update. Affected products include Microsoft Excel 2016, Office 2019, Office 2021 (LTSC), Office 2024 (LTSC), Microsoft 365 Apps for Enterprise, Office Online Server (versions prior to 16.0.10417.20075), and their macOS counterparts. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).

Technical details

The root cause is classified as CWE-822 (Untrusted Pointer Dereference), where Excel fails to properly validate pointer values derived from attacker-controlled data in a malicious file, leading to memory corruption. The attack vector is local, requiring low attack complexity and no special privileges, but does require user interaction — specifically, a victim must open a specially crafted Excel document. The exploitation mechanism aligns with CAPEC-129 (Pointer Manipulation), where a malformed file causes Excel to dereference an attacker-controlled memory address, potentially redirecting execution flow. No public proof-of-concept code has been identified at this time (Microsoft MSRC, Feedly).

Impact

Successful exploitation results in high confidentiality, integrity, and availability impact on the affected system, enabling an attacker to execute arbitrary code in the context of the logged-in user. If the victim has administrative privileges, the attacker could achieve full system compromise, including data theft, installation of malware, or lateral movement within the network. The scope is limited to the affected system (unchanged scope), but the combination of code execution and high-impact triad makes this a significant risk for enterprise environments relying on Microsoft Office (Microsoft MSRC, Feedly).

Exploitation steps

  1. Craft a malicious Excel file: An attacker creates a specially crafted .xlsx or .xls file containing malformed data structures designed to supply an untrusted pointer value during Excel's file parsing routines.
  2. Deliver the file to the target: The attacker distributes the malicious file via phishing email, malicious download link, or shared network drive, relying on social engineering to convince the victim to open it.
  3. Victim opens the file: When the target opens the document in a vulnerable version of Microsoft Excel, the application processes the malformed content and dereferences the attacker-controlled pointer.
  4. Achieve code execution: The untrusted pointer dereference corrupts memory or redirects execution flow, allowing the attacker to execute arbitrary code in the security context of the victim user, potentially enabling payload delivery, persistence, or further lateral movement (Microsoft MSRC, Feedly).

Indicators of compromise

  • File System: Unexpected or newly created executable files, scripts, or DLLs in user temp directories (%TEMP%, %APPDATA%) following the opening of an Excel document; suspicious .xlsx/.xls files received via email or downloaded from untrusted sources.
  • Process: Unusual child processes spawned by EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe); Excel process making unexpected outbound network connections.
  • Network: Outbound connections from EXCEL.EXE to unknown or suspicious IP addresses or domains shortly after a file is opened.
  • Logs: Windows Event Logs showing application crashes or faulting module entries related to EXCEL.EXE; security logs recording new process creation events with EXCEL.EXE as the parent process.

Mitigation and workarounds

Microsoft released patches on December 9, 2025, as part of the December 2025 Patch Tuesday update. Specific fixed versions include Microsoft Excel 2016 (build 16.0.5530.1000 and later) and Office Online Server (build 16.0.10417.20075 and later); all other affected products should be updated via Microsoft Update or the Office Deployment Tool to the latest available build (Microsoft MSRC). As interim mitigations, organizations should disable macros, implement email filtering to block unsolicited Office file attachments, and train users to avoid opening Excel files from untrusted sources. Enabling Microsoft Defender's Attack Surface Reduction (ASR) rules to block Office applications from creating child processes can also reduce exploitation risk (Feedly).

Community reactions

The vulnerability was covered as part of broader December 2025 Patch Tuesday roundups by multiple security outlets. Bleeping Computer noted the December 2025 update addressed 57 flaws including 3 zero-days, with CVE-2025-62561 among the Excel-specific issues (BleepingComputer). Zero Day Initiative (ZDI) included it in their December 2025 security update review (ZDI Blog). Sophos and Rapid7 also published Patch Tuesday analyses covering this vulnerability, with no specific researcher commentary singling it out as particularly novel or immediately dangerous given the absence of a public PoC (Sophos, Rapid7).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management