CVE-2025-60727Disclosure(microsoft / 365_apps)

MEDIUMCVSS 7.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft 365_apps systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_apps
  • excel
  • office
  • office_long_term_servicing_channel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-06-29); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
365_appsexcelofficeoffice_long_term_servicing_channeloffice_online_server

5 versions affected across 5 products

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-06-27: 1Mentions · 2026-06-29: 2Mentions · 2026-06-30: 2Mentions · 2026-07-06: 1Mentions · 2026-07-11: 1Active Exploitation · 2026-06-30: 1Patch / Workaround · 2026-06-29: 2Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-07-11: 1Technical Details · 2026-06-27: 1Technical Details · 2026-06-29: 2Technical Details · 2026-06-30: 2Technical Details · 2026-07-06: 1Technical Details · 2026-07-11: 106-2706-2906-3007-0607-11
Signal classification4 categories
Disclosure
342.9%
Patch
228.6%
General
114.3%
Active Exploitation
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-06-271
General1
2026-06-292
Disclosure1Patch1
2026-06-302
Active Exploitation1Disclosure1
2026-07-061
Disclosure1
2026-07-111
Patch1
Full discourse7 posts
  • kmkz@kmkz_security
    General

    CVE-2025-60727: Microsoft 365 Apps RCE Vulnerability - by @SentinelOne https://www.sentinelone.com/vulnerability-database/cve-2025-60727/

    Post summary

    The notice merely references the CVE-2025-60727 RCE in Microsoft 365 Apps, pointing to a SentinelOne database entry without providing detailed technical or exploit information.

    011037243.4K
    19.7K followersView on X
  • elhacker.NET@elhackernet
    Active Exploitation

    Vulnerabilidad RCE de Microsoft 365 explotada con archivo Excel malicioso Microsoft ha revelado una vulnerabilidad crítica de ejecución remota de código (CVE-2025-60727) en su ecosistema de Office https://blog.elhacker.net/2026/06/vulnerabilidad-rce-de-microsoft-365.html

    Post summary

    Microsoft disclosed that CVE-2025-60727, a critical RCE flaw in the Office 365 ecosystem, is actively being exploited through malicious Excel files.

    01003093.9K
    141.7K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Microsoft 365 Apps の RCE 脆弱性 CVE-2025-60727:細工された Excel ファイルとコード実行 https://iototsecnews.jp/2026/06/29/microsoft-365-apps-rce-vulnerability-lets-attackers-execute-code-via-malicious-excel-files/ Microsoft Office 製品に潜む脆弱性 CVE-2025-60727 は、Excel がファイルを処理する際にデータの長さやオフセット値を適切に検証しないことが原因で発生します。この検証不備により、割り当てられたバッファの境界外にあるメモリが読み込まれ、メモリ破損が引き起こされます。攻撃者が用意した不正なスプレッドシートを開くだけで、利用中のユーザーと同じ権限で任意のコードが実行されてしまう危険性があります。業務で多用される Excel のファイル解析メカニズムそのものに起因する問題であるため、影響範囲が広く注意が必要です。ご利用のチームは、ご注意ください。 #365Apps #CVE202560727 #Microsoft #Vulnerability

    Post summary

    The article discloses CVE‑2025‑60727, an Excel file parsing flaw that can cause RCE through buffer overflow; it provides technical details but no PoC, exploit, patch, or evidence of active exploitation.

    01000152
    500 followersView on X
  • くろん|情シスAIラボ@josys_AI_labo
    Disclosure

    Excelを開くだけでPC乗っ取り。 笑えない話だけど、これが現実。 CVE-2025-60727。 Microsoft Excelの境界外読み取り脆弱性。 影響範囲が地味に広い。 Microsoft 365 Apps Excel 2016 Office 2019 Office LTSC 2021/2024 Office Online Server 全部対象。 認証もいらない。 メール添付を開く、それだけ。 今すぐ更新プログラムを当てる。 Click-to-Runなら最新に保つ。 それだけで大半は防げる。

    Post summary

    The post announces the out‑of‑bounds read flaw in Microsoft Excel (CVE‑2025‑60727) and urges users to apply the latest patch or keep Click‑to‑Run updated.

    10000170
    18 followersView on X
  • ThreadLinqs@threadlinqs
    Patch

    One crafted Excel file, one click - CVE-2025-60727 turns Office file parsing into code execution. Patch now. https://intel.threadlinqs.com/threat/TL-2026-1205 #ThreatIntel #CVE_2025_60727 #Excel #Phishing https://t.co/wKswVg819t

    Post summary

    The tweet urges applying the patch for CVE-2025-60727, an RCE via crafted Excel files, but provides no PoC, code, or evidence of active exploitation.

    0000069
    100 followersView on X
  • TECHEPAGES@techepages
    Patch

    📊 A critical RCE flaw (CVE-2025-60727) in Microsoft Excel lets attackers execute code just by tricking users into opening a malicious file, no auth or elevated privileges needed. Affects Microsoft 365 Apps, Excel 2016, Office 2019/LTSC 2021/2024. 🛡️ Microsoft's already patched it — update Office now and enforce Protected View on files from external sources.

    Post summary

    Microsoft Excel CVE-2025-60727 is a critical RCE flaw that has already been patched; users should update Office and enforce Protected View.

    0000046
    21 followersView on X
  • The Daily Tech Feed@dailytechonx
    Disclosure

    A critical RCE vulnerability (CVE-2025-60727) in Microsoft 365 Apps allows attackers to execute code via malicious Excel files. This flaw affects multiple Office versions and underscores the persistent threat of document-based attacks. Users are urged to apply security updates promptly to mitigate risks. #Microsoft365 #Excel #RCE #CyberSecurity #Phishing #SecurityUpdate https://thedailytechfeed.com/critical-rce-vulnerability-in-microsoft-365-apps-exploited-via-malicious-excel-files/

    Post summary

    The post announces a critical RCE flaw in Microsoft 365 Apps that can be triggered through malicious Excel files and urges users to install security updates.

    0000062
    442 followersView on X
CPE platform detail13 entries

13 of 13 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_apps--x64
Appmicrosoft365_apps--x86
Appmicrosoftexcel2016-x64
Appmicrosoftexcel2016-x86
Appmicrosoftoffice2019-x64
Appmicrosoftoffice2019-x86
Appmicrosoftoffice_long_term_servicing_channel2021-x64
Appmicrosoftoffice_long_term_servicing_channel2021-x86
Appmicrosoftoffice_long_term_servicing_channel2021macos-
Appmicrosoftoffice_long_term_servicing_channel2024-x64
Appmicrosoftoffice_long_term_servicing_channel2024-x86
Appmicrosoftoffice_long_term_servicing_channel2024macos-
Appmicrosoftoffice_online_server---

Explore more