CVE-2025-62555
vulnerability analysis and mitigation

Overview

CVE-2025-62555 is a use-after-free vulnerability in Microsoft Office Word that allows an unauthorized local attacker to execute arbitrary code when a user opens a crafted document. It was disclosed and patched on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday. Affected products include Microsoft Word 2016, Microsoft Office 2019, Office 2021, Office 2024, Microsoft 365 Apps for Enterprise (x86/x64), Office LTSC 2021/2024 (Windows and macOS), SharePoint Server 2016, and SharePoint Server 2019. The vulnerability carries a CVSS v3.1 base score of 7.0 (High) (Microsoft MSRC, Feedly).

Technical details

The root cause is a use-after-free condition (CWE-416) in Microsoft Office Word's document processing logic, where memory that has been freed is subsequently accessed, enabling an attacker to control program execution flow. Exploitation requires the victim to open a specially crafted document locally, making user interaction a prerequisite. The attack vector is local (AV:L) with high attack complexity (AC:H) and no privileges required (PR:N), meaning an attacker must deliver a malicious file to the target and rely on social engineering to trigger it. No public proof-of-concept or technical write-up detailing the specific vulnerable code path has been published as of the disclosure date (Microsoft MSRC, ZDI Blog).

Impact

Successful exploitation could allow an attacker to execute arbitrary code in the context of the current user, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker could potentially gain unauthorized access to sensitive documents, install malware, or take control of the affected Word application or system. The scope is limited to the local machine (S:U), but a compromised endpoint could serve as a foothold for further lateral movement within a network (Microsoft MSRC, Feedly).

Exploitation steps

  1. Craft a malicious document: An attacker creates a specially crafted Word document (.doc/.docx) designed to trigger the use-after-free condition in Microsoft Office Word's document parsing engine.
  2. Deliver the payload: The attacker distributes the malicious document via phishing email, malicious download link, or shared network drive, targeting users running a vulnerable version of Microsoft Office Word.
  3. Social engineering: The attacker convinces the victim to open the document, potentially bypassing Protected View warnings by disguising the file as a legitimate business document.
  4. Trigger the vulnerability: Upon opening, the document triggers the use-after-free condition, causing Word to access previously freed memory controlled by the attacker.
  5. Achieve code execution: The memory corruption allows the attacker to redirect execution flow to attacker-controlled shellcode or a payload, executing arbitrary code in the context of the logged-in user (Microsoft MSRC, Feedly).

Indicators of compromise

  • File System: Unexpected or newly created files in %TEMP%, %APPDATA%, or Office cache directories following the opening of an untrusted Word document; suspicious .doc/.docx files received from unknown sources.
  • Process: Unusual child processes spawned by WINWORD.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe); Word process exhibiting abnormal memory access patterns or crashes.
  • Logs: Windows Event Log entries (Event ID 1000/1001) indicating application crashes or faults in WINWORD.EXE; Windows Defender or AV alerts triggered upon opening a specific document.
  • Network: Unexpected outbound network connections from WINWORD.EXE to external IP addresses or domains shortly after a document is opened.

Mitigation and workarounds

Microsoft released security updates on December 9, 2025 to address this vulnerability. Affected users should apply the following patches: Microsoft Word 2016 to version ≥16.0.5530.1000, SharePoint Server 2016 to ≥16.0.5530.1000, SharePoint Server 2019 to ≥16.0.10417.20075, and Microsoft 365 Apps / Office 2019/2021/2024 via the Office Security Releases channel (https://aka.ms/OfficeSecurityReleases). As interim mitigations, organizations should enable Protected View for documents from untrusted sources, restrict opening of Office files from unknown or external senders, apply least-privilege principles for Office users, and use application allowlisting (Microsoft MSRC, Feedly).

Community reactions

The vulnerability was covered as part of broader December 2025 Patch Tuesday reporting. BleepingComputer noted it among the 57 flaws fixed that month, while the Zero Day Initiative (ZDI) included it in their December 2025 security update review. Sophos and Rapid7 also covered the patch cycle in their respective blog posts. No specific researcher commentary or significant social media discussion focused exclusively on CVE-2025-62555 has been identified, as attention was largely directed at the three zero-days patched in the same release (BleepingComputer, ZDI Blog, Sophos, Rapid7).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management