CVE-2025-60727

Published Nov 11, 2025

Last updated 9 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-60727 is an out-of-bounds read vulnerability found in Microsoft Office Excel, which can enable local code execution. An attacker can exploit this flaw by creating a specially crafted malicious Excel file. When a victim opens this file, the vulnerability is triggered, allowing the attacker to execute arbitrary code within the context of the current user. This vulnerability impacts several Microsoft Office product lines, including Microsoft 365 Apps, Excel 2016, Office 2019, Office LTSC 2021, Office LTSC 2024, and Office Online Server. Exploitation requires user interaction, but it does not necessitate authentication or elevated privileges on the target system.

Description
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Source
secure@microsoft.com
NVD status
Analyzed
Products
365_apps, excel, office, office_long_term_servicing_channel, office_online_server

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-125

Social media

Hype score
Not currently trending
  1. One crafted Excel file, one click - CVE-2025-60727 turns Office file parsing into code execution. Patch now. https://t.co/3eFwwG2B3d #ThreatIntel #CVE_2025_60727 #Excel #Phishing https://t.co/wKswVg819t

    @threadlinqs

    11 Jul 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Microsoft 365 Apps の RCE 脆弱性 CVE-2025-60727:細工された Excel ファイルとコード実行 https://t.co/NotJ5w97iH Microsoft Office 製品に潜む脆弱性 CVE-2025-60727 は、Excel

    @iototsecnews

    6 Jul 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Excelを開くだけでPC乗っ取り。 笑えない話だけど、これが現実。 CVE-2025-60727。 Microsoft Excelの境界外読み取り脆弱性。 影響範囲が地味に広い。 Microsoft 365 Apps Excel 2016 Office 2019 Office LTSC 2021/2024 Office Online Server

    @josys_AI_labo

    30 Jun 2026

    114 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. Vulnerabilidad RCE de Microsoft 365 explotada con archivo Excel malicioso Microsoft ha revelado una vulnerabilidad crítica de ejecución remota de código (CVE-2025-60727) en su ecosistema de Office https://t.co/YYPrxIyTc0

    @elhackernet

    30 Jun 2026

    3586 Impressions

    10 Retweets

    30 Likes

    8 Bookmarks

    0 Replies

    0 Quotes

  5. 📊 A critical RCE flaw (CVE-2025-60727) in Microsoft Excel lets attackers execute code just by tricking users into opening a malicious file, no auth or elevated privileges needed. Affects Microsoft 365 Apps, Excel 2016, Office 2019/LTSC 2021/2024. 🛡️ Microsoft's already p

    @techepages

    29 Jun 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Microsoft 365 AppsのExcelに、悪意あるスプレッドシートを開くだけでログイン中ユーザー権限の任意コード実行につながる脆弱性CVE-2025-60727が公表され、企業環境で懸念が広がっている。

    @yousukezan

    29 Jun 2026

    3062 Impressions

    8 Retweets

    29 Likes

    17 Bookmarks

    0 Replies

    1 Quote

  7. CVE-2025-60727: Microsoft 365 Apps RCE Vulnerability - by @SentinelOne https://t.co/t4U82eYVCT

    @kmkz_security

    27 Jun 2026

    1958 Impressions

    9 Retweets

    20 Likes

    14 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.