CVE-2025-60727: Microsoft 365 Apps Excel Out-of-Bounds Read Enables Remote Code Execution — Threadlinqs Intelligence
As of 2026-07-11, CVE-2025-60727: Microsoft 365 Apps Excel Out-of-Bounds Read Enables Remote Code Execution is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-1205 · Severity: HIGH · CVSS: 7.8 · Status: ACTIVE · Category: VULNERABILITY
An out-of-bounds read vulnerability (CWE-125) in how Microsoft Excel parses crafted spreadsheet files allows an attacker to execute arbitrary code in the context of the current user when a victim
CVE-2025-60727 is a locally-exploitable memory-safety vulnerability (CWE-125, out-of-bounds read) in Microsoft Excel's file-parsing engine, affecting Microsoft 365 Apps (Enterprise, x86/x64), Excel 2016, Office 2019, Office LTSC 2021, Office LTSC 2024, and Office Online Server on Windows and macOS. The root cause is insufficient validation of length and offset values while Excel parses internal binary/OOXML spreadsheet structures (.xls/.xlsx). When Excel processes a specially crafted file, it reads memory beyond the bounds of an allocated buffer; an attacker who controls the malformed structure can leverage this out-of-bounds read to influence subsequent execution flow and ultimately achieve arbitrary code execution running with the current user's privileges (CIA impact: High/High/High).
Exploitation requires no authentication and no elevated privileges (PR:N), but does require user interaction (UI:R) — the victim must open the malicious file — which places this squarely in the phishing-delivered document category rather than a zero-click threat. Microsoft's CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, base score 7.8) reflects a Local attack vector because exploitation occurs through local file parsing once the file is opened on the victim's machine, with Low attack complexity and no special conditions beyond the malformed file itself.
The likely attack chain: an adversary crafts a malicious .xls/.xlsx file with malformed internal structures (e.g., anomalous OLE objects, corrupted record length/offset fields), delivers it via a phishing email disguised as an invoice, business report, or shared document, or via file-sharing/drive-by download vectors, and waits for the victim to open it in Excel (desktop client, Microsoft 365 Apps, or Office Online Server rendering). Upon opening, the parsing logic reads past the allocated buffer, corrupting adjacent memory or leaking pointer/heap layout information that the attacker's crafted payload uses to redirect execution and run arbitrary code in the security context of the logged-on user — enabling follow-on activity such as dropper execution, persistence establishment, credential access, and lateral movement.
As of the source article date (2026-06-29) there is no public proof-of-concept exploit code and no confirmed in-the-wild/active exploitation; the CVE is not present in the CISA Known Exploited Vulnerabilities (KEV) catalog (checked against the 2026-07-10 KEV release, 1,637 entries). EPSS scoring is low (~0.05-0.49% depending on source/date), consistent with a vulnerability that is patched but not yet weaponized publicly. The vulnerability was first published by NVD/MSRC on 2025-11-11 and last updated 2026-06-17. Given the broad Microsoft 365/Office product footprint, the phishing-friendly delivery model, and historical precedent of Office memory-corruption bugs being weaponized after patch analysis (n-day exploitation via patch diffing), this threat remains a high-signal tracking candidate for detection engineering and patch-compliance monitoring despite the absence of confirmed active exploitation.
Target sectors: government administration, finance, health, manufacturing, technology, education, legal, retail
Target regions: North America, Europe, Asia-Pacific, Global
Detections & IOCs
As of 2026-08-17, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2025-60727, T1598, T1588, T1587, T1566, T1204, T1203, T1059, T1547, T1137, T1068