
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62554 is a type confusion (CWE-843) vulnerability in Microsoft Office that allows an unauthorized local attacker to execute arbitrary code. It was disclosed and patched on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday. Affected products include Microsoft Office 2016, 2019, 2021, 2024 (LTSC and standard), Microsoft 365 Apps for Enterprise, Office for Android, Office for macOS (2021 and 2024), and Microsoft 365 Copilot for Android. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) per Microsoft, though ENISA rates it 8.4 (High) (Microsoft MSRC, Tenable Blog).
The vulnerability is classified as CWE-843 (Access of Resource Using Incompatible Type / 'Type Confusion'), meaning the application accesses a memory resource using a type that is incompatible with the actual type of the object, leading to memory corruption and potential code execution. Notably, the Preview Pane in Microsoft Office is identified as an attack vector — an attacker can trigger remote code execution by sending a specially crafted email or document that is merely previewed, without requiring the victim to open, read, or click any links (Feedly/Cryptobivash, Microsoft MSRC). The attack vector is listed as Local (AV:L) in the CVSS scoring, with low attack complexity and low privileges required, and no user interaction needed beyond previewing content (Feedly).
Successful exploitation results in full compromise of the affected system's confidentiality, integrity, and availability — an attacker can execute arbitrary code in the context of the Office application. Because the Preview Pane is an attack vector, exploitation can be achieved without the victim actively opening a malicious file, significantly lowering the bar for mass exploitation in enterprise email environments. The vulnerability affects a broad range of platforms including Windows (x86/x64), macOS, and Android, expanding the potential attack surface across enterprise and consumer deployments (Microsoft MSRC, Feedly/Cryptobivash).
WINWORD.EXE, OUTLOOK.EXE) such as cmd.exe, powershell.exe, wscript.exe, or network-connecting processes without user initiation.mso.dll, wwlib.dll) with access violation or type mismatch errors; crash dump files generated in %LOCALAPPDATA%\CrashDumps or %TEMP%.%TEMP%, %APPDATA%, or startup folders by Office processes; new scheduled tasks or registry run keys created by Office-spawned processes.HKCU\Software\Microsoft\Windows\CurrentVersion\Run entries created around the time of Office Preview Pane activity.Microsoft released patches for CVE-2025-62554 on December 9, 2025, as part of the December 2025 Patch Tuesday. Affected users should update to the latest versions via Microsoft Update or the Office Security Releases page (https://aka.ms/OfficeSecurityReleases); for Office 2016, the fixed version is 16.0.5530.1001 or later. As a temporary workaround, disabling the Preview Pane in Outlook can reduce exposure to the Preview Pane attack vector. Organizations should prioritize patching all Office installations across Windows, macOS, and Android platforms, with particular urgency for enterprise deployments using Microsoft 365 Apps or LTSC versions (Microsoft MSRC, Tenable Blog).
The December 2025 Patch Tuesday received broad coverage from the security community, with analysts at Tenable, Qualys, Rapid7, CrowdStrike, Sophos, and Zero Day Initiative (ZDI) publishing detailed reviews of the update cycle (Tenable Blog, ZDI Blog, BleepingComputer). CVE-2025-62554 was specifically highlighted by multiple outlets for its Preview Pane attack vector, which lowers the exploitation barrier significantly compared to typical Office vulnerabilities requiring file execution. Krebs on Security and Cisco Talos also covered the December 2025 Patch Tuesday, noting the breadth of Office-related fixes (KrebsOnSecurity, Talos Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."