
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62564 is an out-of-bounds read vulnerability in Microsoft Office Excel that allows an unauthorized attacker to execute code locally. Disclosed on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday, it affects Microsoft Excel 2016, Office 2019, Office 2021, Office 2024, Microsoft 365 Apps for Enterprise, Office LTSC 2021/2024 (Windows and macOS), and Office Online Server (versions prior to 16.0.10417.20075). It carries a CVSS v3.1 base score of 7.8 (High) (MSRC Advisory, Feedly).
The vulnerability is classified as CWE-125 (Out-of-bounds Read), mapped to CAPEC-540 (Overread Buffers). An attacker exploits this flaw by crafting a malicious Excel document that, when opened by a victim, triggers an out-of-bounds memory read in Excel's file parsing logic, ultimately enabling local code execution. Exploitation requires user interaction — specifically, a user must open a specially crafted file — and no elevated privileges are required on the part of the attacker. No public proof-of-concept or detailed technical write-up has been identified at this time (MSRC Advisory, Feedly).
Successful exploitation results in high impact to confidentiality, integrity, and availability of the affected system, as an attacker can execute arbitrary code in the context of the logged-in user. This could allow an attacker to install malware, access sensitive data, modify files, or use the compromised system as a pivot point for lateral movement within a network. The scope is limited to the local system (unchanged scope), but the breadth of affected products — including widely deployed Microsoft 365 Apps for Enterprise — means a large number of endpoints could be at risk (MSRC Advisory, Feedly).
EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe) without user initiation.%TEMP%, %APPDATA%, or Office startup folders shortly after opening an Excel document; new scheduled tasks or autorun entries created by Office processes.EXCEL.EXE; security logs showing process creation events with Office applications as parent processes for unusual child processes.Microsoft released patches on December 9, 2025, as part of the December 2025 Patch Tuesday. Users should apply the relevant security updates immediately: Excel 2016 should be updated to version 16.0.5530.1000 or later, and Office Online Server should be updated to version 16.0.10417.20075 or later; Microsoft 365 Apps, Office LTSC 2021/2024, and Office 2019/2024 users should apply the latest updates via Microsoft Update or the Office Security Releases page. As interim mitigations, organizations should restrict users from opening Excel files from untrusted or unknown sources, enforce Protected View settings in Office, and ensure Microsoft Defender (or equivalent) has up-to-date signatures (MSRC Advisory, Feedly).
The vulnerability was covered as part of broader December 2025 Patch Tuesday roundups by multiple security outlets. BleepingComputer noted the December 2025 update addressed 57 flaws including 3 zero-days, with CVE-2025-62564 among the Excel-specific issues (BleepingComputer). Zero Day Initiative (ZDI) and Sophos also published December 2025 Patch Tuesday reviews covering the update batch (ZDI Blog, Sophos News). No specific researcher commentary or significant social media discussion focused exclusively on CVE-2025-62564 has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."