CVE-2025-62200

7.8

Microsoft · Excel

An untrusted pointer dereference vulnerability in Microsoft Excel allows an unauthorized attacker to achieve local code execution.

Executive summary

A critical untrusted pointer dereference vulnerability in Microsoft Excel permits unauthorized local code execution, posing a significant risk to system integrity.

Vulnerability

This flaw involves an untrusted pointer dereference (CWE-822) within the Excel application, which can be triggered by an unauthorized attacker. Successful exploitation allows the attacker to execute arbitrary code locally on the host machine.

Business impact

The ability for an unauthorized attacker to execute local code represents a severe security compromise. This vulnerability could lead to total system takeover, unauthorized access to sensitive data, and potential lateral movement within the network. With a CVSS score of 7.8, the risk is classified as High, necessitating prompt attention to prevent potential data breaches or operational disruption.

Remediation

Immediate Action: Organizations must apply the latest security updates provided by Microsoft via the official update guide at https://aka.ms/OfficeSecurityReleases.

Proactive Monitoring: Security teams should monitor endpoint logs for suspicious process execution patterns originating from Excel or unexpected file modifications.

Compensating Controls: Ensure that Office applications are run with the least privilege necessary and utilize endpoint protection solutions to detect and block malicious code execution attempts.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for local code execution, this vulnerability poses a serious threat to workstation security. IT administrators should prioritize the deployment of the vendor-supplied patches across all affected Excel and Office installations. Regular patching cycles and adherence to the principle of least privilege remain the most effective defenses against this class of memory-related vulnerabilities.

More Microsoft CVEs

Sources