AI description
CVE-2025-60727 is an out-of-bounds read vulnerability found in Microsoft Office Excel, which can enable local code execution. An attacker can exploit this flaw by creating a specially crafted malicious Excel file. When a victim opens this file, the vulnerability is triggered, allowing the attacker to execute arbitrary code within the context of the current user. This vulnerability impacts several Microsoft Office product lines, including Microsoft 365 Apps, Excel 2016, Office 2019, Office LTSC 2021, Office LTSC 2024, and Office Online Server. Exploitation requires user interaction, but it does not necessitate authentication or elevated privileges on the target system.
- Description
- Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
- Products
- 365_apps, excel, office, office_long_term_servicing_channel, office_online_server
CVSS 3.1
- Type
- Secondary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
- secure@microsoft.com
- CWE-125
- Hype score
- Not currently trending
One crafted Excel file, one click - CVE-2025-60727 turns Office file parsing into code execution. Patch now. https://t.co/3eFwwG2B3d #ThreatIntel #CVE_2025_60727 #Excel #Phishing https://t.co/wKswVg819t
@threadlinqs
11 Jul 2026
53 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft 365 Apps の RCE 脆弱性 CVE-2025-60727:細工された Excel ファイルとコード実行 https://t.co/NotJ5w97iH Microsoft Office 製品に潜む脆弱性 CVE-2025-60727 は、Excel
@iototsecnews
6 Jul 2026
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Excelを開くだけでPC乗っ取り。 笑えない話だけど、これが現実。 CVE-2025-60727。 Microsoft Excelの境界外読み取り脆弱性。 影響範囲が地味に広い。 Microsoft 365 Apps Excel 2016 Office 2019 Office LTSC 2021/2024 Office Online Server
@josys_AI_labo
30 Jun 2026
114 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Vulnerabilidad RCE de Microsoft 365 explotada con archivo Excel malicioso Microsoft ha revelado una vulnerabilidad crítica de ejecución remota de código (CVE-2025-60727) en su ecosistema de Office https://t.co/YYPrxIyTc0
@elhackernet
30 Jun 2026
3586 Impressions
10 Retweets
30 Likes
8 Bookmarks
0 Replies
0 Quotes
📊 A critical RCE flaw (CVE-2025-60727) in Microsoft Excel lets attackers execute code just by tricking users into opening a malicious file, no auth or elevated privileges needed. Affects Microsoft 365 Apps, Excel 2016, Office 2019/LTSC 2021/2024. 🛡️ Microsoft's already p
@techepages
29 Jun 2026
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft 365 AppsのExcelに、悪意あるスプレッドシートを開くだけでログイン中ユーザー権限の任意コード実行につながる脆弱性CVE-2025-60727が公表され、企業環境で懸念が広がっている。
@yousukezan
29 Jun 2026
3062 Impressions
8 Retweets
29 Likes
17 Bookmarks
0 Replies
1 Quote
CVE-2025-60727: Microsoft 365 Apps RCE Vulnerability - by @SentinelOne https://t.co/t4U82eYVCT
@kmkz_security
27 Jun 2026
1958 Impressions
9 Retweets
20 Likes
14 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*",
"matchCriteriaId": "3259EBFE-AE2D-48B8-BE9A-E22BBDB31378",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*",
"matchCriteriaId": "CD25F492-9272-4836-832C-8439EBE64CCF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:x64:*",
"matchCriteriaId": "CD88F667-6773-4DB7-B6C3-9C7B769C0808",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:x86:*",
"matchCriteriaId": "B342EF98-B414-44D0-BAFB-FCA24294EECE",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:x64:*",
"matchCriteriaId": "CF5DDD09-902E-4881-98D0-CB896333B4AA",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:x86:*",
"matchCriteriaId": "26A3B226-5D7C-4556-9350-5222DC8EFC2C",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x64:*",
"matchCriteriaId": "851BAC4E-9965-4F40-9A6C-B73D9004F4C1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x86:*",
"matchCriteriaId": "23B2FA23-76F4-4D83-A718-B8D04D7EA37B",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:macos:*:*",
"matchCriteriaId": "BF0E8112-5B6F-4E55-8E40-38ADCF6FC654",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x64:*",
"matchCriteriaId": "D31E509A-0B2E-4B41-88C4-0099E800AFE6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x86:*",
"matchCriteriaId": "017A7041-BEF1-4E4E-AC8A-EFC6AFEB01FE",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:macos:*:*",
"matchCriteriaId": "EF3E56B5-E6A6-4061-9380-D421E52B9199",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_online_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "5B5A0D24-857F-4078-A9C3-D4F2EEEF283F",
"versionEndExcluding": "16.0.10417.20068",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]