CVE-2025-60728
published 2025-11-11CVE-2025-60728: Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
PriorityP422medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
0.70%
49.5th percentile
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2024 | >= 16.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_for_mac_2024 | >= 16.0.0 < 16.103.25110922 | 16.103.25110922 |
| microsoft | office_long_term_servicing_channel | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_office_ltsc_2024_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2024_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_for_mac_2024 | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
vendor_msrc4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Excel Information Disclosure Vulnerability
vendor_msrc·2025-11-11·CVSS 4.3
CVE-2025-60728 [MEDIUM] CWE-822 Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
Description: Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to no loss of confidentiality (C:N) and integrity (I:N), but could lead to some loss of availability (A:L). What does that mean for this vulnerability?
While we cannot rule out the impact to Confidentiality, Integrity, and Availability, the ability to exploit this vulnerability by itself is limited. An attacker would need to
GHSA
GHSA-2mg4-fmh8-qqh3: Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network
ghsa_unreviewed·2025-11-11
CVE-2025-60728 [MEDIUM] CWE-125 GHSA-2mg4-fmh8-qqh3: Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
No detection rules found.
No public exploits indexed.
2025-11-11
Published