CVE-2025-62563

7.8

Microsoft · Microsoft Office Excel

A use after free vulnerability in Microsoft Office Excel permits an unauthorized attacker to achieve local code execution.

Executive summary

A use after free vulnerability in Microsoft Office Excel exposes users to potential local code execution risks if a malicious file is processed.

Vulnerability

This vulnerability is a use after free memory corruption flaw (CWE-416) that can be triggered when the application improperly handles specific objects in memory, requiring user interaction to execute.

Business impact

The exploitation of this vulnerability allows for local code execution, which could lead to full system compromise, data exfiltration, or the installation of persistent threats. With a CVSS score of 7.8, this high severity flaw poses a significant risk to organizational integrity, as successful execution allows an attacker to gain the same privileges as the logged-in user.

Remediation

Immediate Action: Apply the relevant security updates provided by Microsoft via the official update guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62563.

Proactive Monitoring: Review endpoint security logs for anomalous Excel process behavior or unexpected child process spawning.

Compensating Controls: Ensure that Protected View and Application Guard are enabled for all Office users to restrict the execution of untrusted files.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for code execution and the ubiquity of Excel in enterprise environments, administrators must prioritize the deployment of these security patches. Users should exercise caution when opening unexpected or untrusted Excel workbooks until the update is applied across the environment.

More Microsoft CVEs

Sources