
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62553 is a use-after-free vulnerability in Microsoft Office Excel that allows an unauthorized local attacker to execute arbitrary code. It was disclosed and patched on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday security updates. Affected products include Microsoft Excel 2016, Office 2019, Office 2021, Office 2024, Office LTSC 2021/2024 (Windows x86/x64 and macOS), and Microsoft 365 Apps for Enterprise. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (MSRC Advisory, Feedly).
The vulnerability is classified as CWE-416 (Use After Free), meaning Excel improperly accesses memory after it has been freed during file processing operations. Exploitation requires a user to open a specially crafted Excel file, at which point the use-after-free condition is triggered, enabling code execution in the context of the logged-in user. The attack vector is local (AV:L), requires no privileges (PR:N), but does require user interaction (UI:R), making social engineering or phishing with malicious Excel attachments the most likely delivery mechanism. No public proof-of-concept or detailed technical write-up has been published as of the disclosure date (MSRC Advisory, ZDI Blog).
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Excel, potentially leading to complete system compromise, data theft, malware installation, or lateral movement within a network. All three security pillars are affected at HIGH severity — confidentiality, integrity, and availability — meaning an attacker could read sensitive data, modify files, or render the system unavailable. The scope is limited to the affected system (S:U), but privilege escalation or credential harvesting post-exploitation could enable broader network compromise (MSRC Advisory, Feedly).
.xlsx or .xls file designed to trigger a use-after-free condition in Excel's memory management routines during file parsing.EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe) shortly after opening an Excel file.%TEMP%, %APPDATA%, or startup folders by the Excel process; newly created scripts or executables in user-writable directories.EXCEL.EXE to external or unusual IP addresses/domains, particularly after opening an untrusted file.EXCEL.EXE; application crash logs or Dr. Watson/WER reports referencing Excel memory access violations.Microsoft released patches on December 9, 2025 as part of the December 2025 Patch Tuesday update cycle. Affected users should apply the latest security updates immediately via Windows Update or the Microsoft Update Catalog. Specific version targets include: Microsoft Excel 2016 updated to build 16.0.5530.1000 or later; Microsoft 365 Apps for Enterprise, Office 2019, Office 2021, Office 2024, and all LTSC editions should be updated to the versions referenced at https://aka.ms/OfficeSecurityReleases. As interim mitigations, organizations should educate users to avoid opening Excel files from untrusted sources, consider enabling Protected View for files from the internet, and apply application whitelisting policies to restrict Office macro and script execution (MSRC Advisory, Feedly).
The vulnerability was covered as part of broader December 2025 Patch Tuesday roundups by multiple security outlets. BleepingComputer noted it among 57 flaws fixed that month, with the update cycle also addressing 3 zero-days (BleepingComputer). The Zero Day Initiative reviewed the December 2025 updates and included this CVE in their summary (ZDI Blog). Cisco Talos and Sophos also published Patch Tuesday analyses covering the broader update batch (Talos Blog, Sophos Blog). No significant independent researcher commentary or social media controversy specific to CVE-2025-62553 was observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."