cbcvebase.
CVE-2025-60724
published 2025-11-11

CVE-2025-60724: Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

PriorityP269critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
5.79%
92.3th percentile
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Affected

52 ranges· showing 25
VendorProductVersion rangeFixed in
microsoft365_copilot< 16.0.19426.2004416.0.19426.20044
microsoftmicrosoft_office_for_android>= 16.0.1 < 16.0.19426.2004416.0.19426.20044
microsoftmicrosoft_office_ltsc_for_mac_2021>= 16.0.1 < 16.103.2511092216.103.25110922
microsoftmicrosoft_office_ltsc_for_mac_2024>= 16.0.0 < 16.103.2511092216.103.25110922
microsoftoffice_long_term_servicing_channel
microsoftoffice_long_term_servicing_channel
microsoftwindows_10_1607< 10.0.14393.859410.0.14393.8594
microsoftwindows_10_1809< 10.0.17763.802710.0.17763.8027
microsoftwindows_10_21h2< 10.0.19044.657510.0.19044.6575
microsoftwindows_10_22h2< 10.0.19045.657510.0.19045.6575
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.859410.0.14393.8594
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.802710.0.17763.8027
microsoftwindows_10_version_21h2>= 10.0.19044.0 < 10.0.19044.657510.0.19044.6575
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.657510.0.19045.6575
microsoftwindows_11_23h2< 10.0.22631.619910.0.22631.6199
microsoftwindows_11_24h2< 10.0.26100.709210.0.26100.7092
microsoftwindows_11_25h2< 10.0.26200.709210.0.26200.7092
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.619910.0.22631.6199
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.619910.0.22631.6199
microsoftwindows_11_version_24h2>= 10.0.26100.0 < 10.0.26100.717110.0.26100.7171
microsoftwindows_11_version_25h2>= 10.0.26200.0 < 10.0.26200.717110.0.26200.7171
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.280216.1.7601.28021
microsoftwindows_server_2008_service_pack_2>= 6.0.6003.0 < 6.0.6003.236246.0.6003.23624
microsoftwindows_server_2012

Detection & IOCsextracted from sources · hover to see the quote

snort
Snort 2 rules: 65496-65501, 65507-65510
snort
Snort 3 rules: 301343-301345, 301347, 301348
  • CVE-2025-60724 can be triggered by a specially crafted metafile embedded in a document — inspect documents (e.g., Office files) uploaded to or downloaded from web services for anomalous metafile content.
  • Zero-user-interaction exploitation path exists via document upload to web services — monitor web service endpoints that parse/render documents (e.g., image/metafile processing pipelines) for unexpected GDI+ crashes or heap corruption indicators.
  • No privileges required for exploitation against web services — treat unauthenticated document upload requests to metafile-parsing endpoints as high-risk and apply strict input validation/sandboxing.
  • Preview Pane is NOT an attack vector — focus detection on file-open and document-upload code paths rather than preview rendering.
  • ·Exploitation is assessed as 'less likely' by Microsoft and has not been publicly disclosed or observed in the wild as of the November 2025 Patch Tuesday release.
  • ·Snort rules 65496-65501, 65507-65510 (Snort 2) and 301343-301345, 301347, 301348 (Snort 3) cover multiple November 2025 Patch Tuesday vulnerabilities, not exclusively CVE-2025-60724 — validate rule applicability before deployment.
  • ·Additional Snort rules may be released at a future date and current rules are subject to change pending additional information.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_msrc9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.