Microsoft: Microsoft 365 Apps RCE Vulnerability Exploited Using a Malicious Excel File

Microsoft: Microsoft 365 Apps RCE Vulnerability Exploited Using a Malicious Excel File

Microsoft Discloses Critical RCE Vulnerability in Office Suite via Malicious Excel Files

Microsoft has revealed a severe remote code execution (RCE) vulnerability, CVE-2025-60727, affecting multiple versions of its Office ecosystem, including Microsoft 365 Apps, Excel 2016, Office 2019, Office LTSC 2021/2024, and Office Online Server. The flaw, classified as an out-of-bounds read vulnerability (CWE-125), stems from improper memory handling during Excel file parsing, allowing attackers to execute arbitrary code on a victim’s system.

Exploitation requires a user to open a maliciously crafted Excel file, typically delivered via phishing emails disguised as legitimate documents (e.g., invoices or reports). The attack does not require authentication or elevated privileges, making it a high-risk vector for threat actors. Once triggered, the vulnerability enables attackers to gain the same access level as the compromised user, potentially leading to data theft, malware deployment, lateral movement, or full system compromise.

The root cause lies in insufficient validation of length and offset values during file processing, causing Excel to read beyond allocated memory boundaries. Attackers can manipulate this behavior to control execution flow and inject malicious code. Detection relies on monitoring unusual Excel activity, such as unexpected child processes (e.g., command shells), suspicious network connections, or crash reports following file access.

Microsoft released security updates to patch the vulnerability, first documented in the National Vulnerability Database on November 11, 2025, with updates as recent as June 17, 2026. While no active exploitation has been reported, the flaw aligns with common document-based phishing tactics, posing a significant risk to enterprises and individuals alike. Mitigation strategies include enabling Protected View, blocking macros, and restricting untrusted file sources.

Source: https://cybersecuritynews.com/microsoft-365-apps-rce-vulnerability-exploit/

Microsoft cybersecurity rating report: https://www.rankiteo.com/company/microsoft

"id": "MIC1782750368",
"linkid": "microsoft",
"type": "Vulnerability",
"date": "11/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Users of Microsoft 365 Apps, '
                                              'Excel 2016, Office 2019, Office '
                                              'LTSC 2021/2024, Office Online '
                                              'Server',
                        'industry': 'Software',
                        'location': 'Global',
                        'name': 'Microsoft',
                        'size': 'Enterprise',
                        'type': 'Technology Company'}],
 'attack_vector': 'Malicious Excel file (phishing email)',
 'data_breach': {'data_exfiltration': 'Potential',
                 'file_types_exposed': 'Excel files'},
 'date_publicly_disclosed': '2025-11-11',
 'date_resolved': '2026-06-17',
 'description': 'Microsoft has revealed a severe remote code execution (RCE) '
                'vulnerability, CVE-2025-60727, affecting multiple versions of '
                'its Office ecosystem, including Microsoft 365 Apps, Excel '
                '2016, Office 2019, Office LTSC 2021/2024, and Office Online '
                'Server. The flaw, classified as an out-of-bounds read '
                'vulnerability (CWE-125), stems from improper memory handling '
                'during Excel file parsing, allowing attackers to execute '
                'arbitrary code on a victim’s system. Exploitation requires a '
                'user to open a maliciously crafted Excel file, typically '
                'delivered via phishing emails disguised as legitimate '
                'documents. The attack does not require authentication or '
                'elevated privileges, enabling attackers to gain the same '
                'access level as the compromised user, potentially leading to '
                'data theft, malware deployment, lateral movement, or full '
                'system compromise.',
 'impact': {'data_compromised': 'Potential data theft',
            'operational_impact': 'Potential full system compromise, lateral '
                                  'movement, malware deployment',
            'systems_affected': 'Microsoft 365 Apps, Excel 2016, Office 2019, '
                                'Office LTSC 2021/2024, Office Online Server'},
 'post_incident_analysis': {'corrective_actions': 'Security updates to patch '
                                                  'the vulnerability, improved '
                                                  'memory handling in Excel '
                                                  'file parsing.',
                            'root_causes': 'Insufficient validation of length '
                                           'and offset values during Excel '
                                           'file processing, leading to '
                                           'out-of-bounds memory reads.'},
 'recommendations': 'Enable Protected View, block macros, restrict untrusted '
                    'file sources, apply security updates promptly, monitor '
                    'for unusual Excel activity.',
 'references': [{'source': 'National Vulnerability Database'}],
 'response': {'containment_measures': 'Enabling Protected View, blocking '
                                      'macros, restricting untrusted file '
                                      'sources',
              'enhanced_monitoring': 'Monitoring unusual Excel activity (e.g., '
                                     'unexpected child processes, suspicious '
                                     'network connections, crash reports)',
              'remediation_measures': 'Security updates released by Microsoft'},
 'title': 'Critical RCE Vulnerability in Microsoft Office Suite via Malicious '
          'Excel Files (CVE-2025-60727)',
 'type': 'Remote Code Execution (RCE)',
 'vulnerability_exploited': 'CVE-2025-60727 (Out-of-bounds read, CWE-125)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.