CVE-2025-62564
vulnerability analysis and mitigation

Overview

CVE-2025-62564 is an out-of-bounds read vulnerability in Microsoft Office Excel that allows an unauthorized attacker to execute code locally. Disclosed on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday, it affects Microsoft Excel 2016, Office 2019, Office 2021, Office 2024, Microsoft 365 Apps for Enterprise, Office LTSC 2021/2024 (Windows and macOS), and Office Online Server (versions prior to 16.0.10417.20075). It carries a CVSS v3.1 base score of 7.8 (High) (MSRC Advisory, Feedly).

Technical details

The vulnerability is classified as CWE-125 (Out-of-bounds Read), mapped to CAPEC-540 (Overread Buffers). An attacker exploits this flaw by crafting a malicious Excel document that, when opened by a victim, triggers an out-of-bounds memory read in Excel's file parsing logic, ultimately enabling local code execution. Exploitation requires user interaction — specifically, a user must open a specially crafted file — and no elevated privileges are required on the part of the attacker. No public proof-of-concept or detailed technical write-up has been identified at this time (MSRC Advisory, Feedly).

Impact

Successful exploitation results in high impact to confidentiality, integrity, and availability of the affected system, as an attacker can execute arbitrary code in the context of the logged-in user. This could allow an attacker to install malware, access sensitive data, modify files, or use the compromised system as a pivot point for lateral movement within a network. The scope is limited to the local system (unchanged scope), but the breadth of affected products — including widely deployed Microsoft 365 Apps for Enterprise — means a large number of endpoints could be at risk (MSRC Advisory, Feedly).

Exploitation steps

  1. Craft malicious document: An attacker creates a specially crafted Excel file (.xls, .xlsx, or similar) designed to trigger an out-of-bounds read in Excel's file parsing routines when processed.
  2. Deliver the file: The attacker distributes the malicious document via phishing email, malicious download link, or other social engineering methods targeting users of affected Excel versions.
  3. User interaction: The victim opens the malicious Excel file using a vulnerable version of Microsoft Excel (e.g., Excel 2016, Office 2019, Microsoft 365 Apps).
  4. Trigger vulnerability: Excel's parser reads beyond the bounds of an allocated memory buffer while processing the crafted file structure, leading to memory corruption.
  5. Code execution: The out-of-bounds read condition is leveraged to achieve arbitrary code execution in the context of the current user, potentially enabling installation of malware, credential theft, or further lateral movement (MSRC Advisory, Feedly).

Indicators of compromise

  • Network: Unexpected outbound connections from Excel or Office processes to unknown external IP addresses or domains following the opening of a document.
  • Process: Unusual child processes spawned by EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe) without user initiation.
  • File System: Unexpected files dropped in %TEMP%, %APPDATA%, or Office startup folders shortly after opening an Excel document; new scheduled tasks or autorun entries created by Office processes.
  • Logs: Windows Event Log entries (Event ID 1000/1001) indicating application crashes or faults in EXCEL.EXE; security logs showing process creation events with Office applications as parent processes for unusual child processes.

Mitigation and workarounds

Microsoft released patches on December 9, 2025, as part of the December 2025 Patch Tuesday. Users should apply the relevant security updates immediately: Excel 2016 should be updated to version 16.0.5530.1000 or later, and Office Online Server should be updated to version 16.0.10417.20075 or later; Microsoft 365 Apps, Office LTSC 2021/2024, and Office 2019/2024 users should apply the latest updates via Microsoft Update or the Office Security Releases page. As interim mitigations, organizations should restrict users from opening Excel files from untrusted or unknown sources, enforce Protected View settings in Office, and ensure Microsoft Defender (or equivalent) has up-to-date signatures (MSRC Advisory, Feedly).

Community reactions

The vulnerability was covered as part of broader December 2025 Patch Tuesday roundups by multiple security outlets. BleepingComputer noted the December 2025 update addressed 57 flaws including 3 zero-days, with CVE-2025-62564 among the Excel-specific issues (BleepingComputer). Zero Day Initiative (ZDI) and Sophos also published December 2025 Patch Tuesday reviews covering the update batch (ZDI Blog, Sophos News). No specific researcher commentary or significant social media discussion focused exclusively on CVE-2025-62564 has been identified.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management