CVE-2025-60727

Published Nov 11, 2025

Last updated 7 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-60727 is an out-of-bounds read vulnerability found in Microsoft Office Excel, which can enable local code execution. An attacker can exploit this flaw by creating a specially crafted malicious Excel file. When a victim opens this file, the vulnerability is triggered, allowing the attacker to execute arbitrary code within the context of the current user. This vulnerability impacts several Microsoft Office product lines, including Microsoft 365 Apps, Excel 2016, Office 2019, Office LTSC 2021, Office LTSC 2024, and Office Online Server. Exploitation requires user interaction, but it does not necessitate authentication or elevated privileges on the target system.

Description
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Source
secure@microsoft.com
NVD status
Analyzed
Products
365_apps, excel, office, office_long_term_servicing_channel, office_online_server

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-125

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

4

Configurations

References

Sources include official advisories and independent security research.