CVE-2025-62552
vulnerability analysis and mitigation

Overview

CVE-2025-62552 is a relative path traversal vulnerability (CWE-23) in Microsoft Office Access that allows an unauthorized local attacker to execute arbitrary code. It was disclosed on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday security update release. Affected products include Microsoft Access 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, and Microsoft 365 Apps for Enterprise (both x86 and x64 editions). The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, BleepingComputer).

Technical details

The vulnerability is rooted in improper handling of file path inputs within Microsoft Office Access, classified as CWE-23 (Relative Path Traversal) and associated with CAPEC-139. By manipulating relative file path references, an attacker can cause Access to load or reference unintended files, ultimately enabling local code execution. Exploitation requires user interaction — a victim must open a specially crafted Access file or perform an action that triggers the vulnerable path-handling logic — but no special privileges are required. Third-party micropatch provider 0patch later released micropatches for this vulnerability, suggesting the underlying mechanism was analyzed in detail by the security research community (Microsoft MSRC, Malware News).

Impact

Successful exploitation grants an attacker the ability to execute arbitrary code in the context of the local user running Microsoft Access, resulting in high confidentiality, integrity, and availability impact. An attacker could read sensitive files, modify data, install malware, or disrupt the affected Office installation. While the attack vector is local and requires user interaction, a compromised endpoint could serve as a foothold for further lateral movement within a network (Microsoft MSRC, Feedly).

Exploitation steps

  1. Craft a malicious Access file: Create a specially crafted Microsoft Access database file (.accdb or .mdb) that contains relative path traversal sequences in file references, linked table paths, or macro/module references designed to redirect Access to load an attacker-controlled file.
  2. Deliver the file to the target: Use social engineering, phishing email, or a malicious download link to deliver the crafted file to a victim running a vulnerable version of Microsoft Access (Access 2016, Office 2019, LTSC 2021/2024, or Microsoft 365 Apps for Enterprise).
  3. Induce user interaction: Convince the victim to open the malicious Access file. The vulnerability requires user interaction to trigger the path traversal logic.
  4. Trigger path traversal: Upon opening, Access processes the manipulated relative path, traversing outside the intended directory to reference or load an attacker-controlled payload (e.g., a malicious DLL or executable).
  5. Achieve code execution: The loaded payload executes in the context of the victim user, granting the attacker arbitrary code execution on the local system (Microsoft MSRC, Malware News).

Indicators of compromise

  • File System: Unexpected .accdb or .mdb files received via email or downloaded from untrusted sources; presence of unusual DLLs or executables in directories adjacent to or referenced by Access database files; new files created in user-writable directories shortly after opening an Access file.
  • Process: Unusual child processes spawned by MSACCESS.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, or unknown executables); Access process loading DLLs from non-standard or user-writable paths.
  • Logs: Windows Event Logs showing process creation events (Event ID 4688) with MSACCESS.EXE as the parent process and unexpected child processes; application crash logs or error events related to Access loading files from unexpected paths.
  • Network: Outbound network connections initiated by MSACCESS.EXE to external IPs or domains (unusual for normal Access usage), potentially indicating a post-exploitation payload phoning home.

Mitigation and workarounds

Microsoft released patches for CVE-2025-62552 on December 9, 2025, as part of the December 2025 Patch Tuesday update cycle. Affected users should apply the latest security updates via Microsoft Update or the Microsoft Update Catalog; Microsoft Access 2016 is patched at version 16.0.5530.1000 or later, while Microsoft 365 Apps, Office 2019, LTSC 2021, and LTSC 2024 should be updated to the latest channel release per the Office Security Releases page. As interim mitigations, organizations should restrict opening Access files from untrusted sources, apply least-privilege principles for Office users, and use endpoint protection solutions to detect suspicious process behavior (Microsoft MSRC, Malware News).

Community reactions

CVE-2025-62552 was covered as part of broader December 2025 Patch Tuesday roundups by multiple security outlets including BleepingComputer, Zero Day Initiative (ZDI), Sophos, Rapid7, and Tenable, though it did not receive individual spotlight coverage given the absence of active exploitation (BleepingComputer, ZDI, Sophos). The most notable community reaction came when 0patch released micropatches for the vulnerability, generating discussion on Reddit's r/SecOpsDaily and Bluesky infosec communities, indicating researcher interest in the underlying mechanism (Reddit, Malware News).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management