
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62555 is a use-after-free vulnerability in Microsoft Office Word that allows an unauthorized local attacker to execute arbitrary code when a user opens a crafted document. It was disclosed and patched on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday. Affected products include Microsoft Word 2016, Microsoft Office 2019, Office 2021, Office 2024, Microsoft 365 Apps for Enterprise (x86/x64), Office LTSC 2021/2024 (Windows and macOS), SharePoint Server 2016, and SharePoint Server 2019. The vulnerability carries a CVSS v3.1 base score of 7.0 (High) (Microsoft MSRC, Feedly).
The root cause is a use-after-free condition (CWE-416) in Microsoft Office Word's document processing logic, where memory that has been freed is subsequently accessed, enabling an attacker to control program execution flow. Exploitation requires the victim to open a specially crafted document locally, making user interaction a prerequisite. The attack vector is local (AV:L) with high attack complexity (AC:H) and no privileges required (PR:N), meaning an attacker must deliver a malicious file to the target and rely on social engineering to trigger it. No public proof-of-concept or technical write-up detailing the specific vulnerable code path has been published as of the disclosure date (Microsoft MSRC, ZDI Blog).
Successful exploitation could allow an attacker to execute arbitrary code in the context of the current user, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker could potentially gain unauthorized access to sensitive documents, install malware, or take control of the affected Word application or system. The scope is limited to the local machine (S:U), but a compromised endpoint could serve as a foothold for further lateral movement within a network (Microsoft MSRC, Feedly).
%TEMP%, %APPDATA%, or Office cache directories following the opening of an untrusted Word document; suspicious .doc/.docx files received from unknown sources.WINWORD.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe); Word process exhibiting abnormal memory access patterns or crashes.WINWORD.EXE; Windows Defender or AV alerts triggered upon opening a specific document.WINWORD.EXE to external IP addresses or domains shortly after a document is opened.Microsoft released security updates on December 9, 2025 to address this vulnerability. Affected users should apply the following patches: Microsoft Word 2016 to version ≥16.0.5530.1000, SharePoint Server 2016 to ≥16.0.5530.1000, SharePoint Server 2019 to ≥16.0.10417.20075, and Microsoft 365 Apps / Office 2019/2021/2024 via the Office Security Releases channel (https://aka.ms/OfficeSecurityReleases). As interim mitigations, organizations should enable Protected View for documents from untrusted sources, restrict opening of Office files from unknown or external senders, apply least-privilege principles for Office users, and use application allowlisting (Microsoft MSRC, Feedly).
The vulnerability was covered as part of broader December 2025 Patch Tuesday reporting. BleepingComputer noted it among the 57 flaws fixed that month, while the Zero Day Initiative (ZDI) included it in their December 2025 security update review. Sophos and Rapid7 also covered the patch cycle in their respective blog posts. No specific researcher commentary or significant social media discussion focused exclusively on CVE-2025-62555 has been identified, as attention was largely directed at the three zero-days patched in the same release (BleepingComputer, ZDI Blog, Sophos, Rapid7).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."