CVE-2025-62560

7.8

Microsoft · Excel

An untrusted pointer dereference vulnerability in Microsoft Excel allows a local attacker to execute arbitrary code.

Executive summary

A critical vulnerability in Microsoft Excel allows local attackers to execute arbitrary code due to an untrusted pointer dereference flaw.

Vulnerability

The vulnerability is caused by an untrusted pointer dereference (CWE-822) and buffer over-read (CWE-126) within the Excel application. An attacker can trigger this flaw locally, typically requiring user interaction to open a malicious file.

Business impact

The exploitation of this vulnerability could lead to a full compromise of the local system, enabling attackers to execute code with the permissions of the current user. Given the CVSS score of 7.8, this represents a high-severity risk that could result in data theft, unauthorized system access, or the deployment of further malware within the corporate network.

Remediation

Immediate Action: Apply the relevant security updates provided by Microsoft in the official security release guide immediately.

Proactive Monitoring: Review system logs for unusual Excel process activity or unexpected crashes that may indicate exploitation attempts.

Compensating Controls: Ensure that Office macro security settings are configured to block untrusted content and utilize endpoint protection software to scan incoming documents for malicious patterns.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations should prioritize the deployment of the provided patches across all affected Excel installations. Given the risk of local code execution, ensure that security updates are pushed to all endpoints to minimize the window of exposure.

More Microsoft CVEs

Sources