CVE-2025-62557
vulnerability analysis and mitigation

Overview

CVE-2025-62557 is a use-after-free (UAF) vulnerability in Microsoft Office that allows a low-privileged local attacker to execute arbitrary code on the affected system. Disclosed on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday, it affects Microsoft Office 2016, 2019, 2021, 2024 (LTSC), Microsoft 365 Apps for Enterprise, Microsoft Office for Android, and Microsoft 365 Copilot for Android across x86, x64, and macOS platforms. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Tenable Blog).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), meaning Microsoft Office improperly accesses memory after it has been freed, potentially allowing an attacker to corrupt heap memory and redirect code execution. Exploitation requires only low privileges and no user interaction, making it particularly dangerous for multi-user environments where a local attacker already has a foothold. The attack vector is local (AV:L), with low attack complexity, meaning no special conditions or race conditions are required beyond having a local account. No public technical write-up or proof-of-concept code has been identified at this time (Microsoft MSRC, Tenable Blog).

Impact

Successful exploitation of CVE-2025-62557 could allow an attacker to execute arbitrary code in the context of the affected Microsoft Office process, resulting in full compromise of confidentiality, integrity, and availability on the target system. An attacker who gains code execution could steal sensitive documents, modify Office files, install persistent malware, or use the compromised system as a pivot point for lateral movement within a network. The broad scope of affected products — spanning Windows (x86/x64), macOS, and Android — significantly widens the potential attack surface (Microsoft MSRC, Feedly).

Mitigation and workarounds

Microsoft released patches for CVE-2025-62557 on December 9, 2025, as part of the December 2025 Patch Tuesday security update. Affected products and their remediation paths include: Microsoft Office 2016 (update to build 16.0.5530.1001 or later), Microsoft Office 2019, 2021, and 2024 LTSC (update via Microsoft Update or the Office Security Releases page at https://aka.ms/OfficeSecurityReleases), and Microsoft 365 Apps for Enterprise (update via standard Microsoft Update channels). As a temporary workaround, Microsoft recommends restricting the opening of files from untrusted sources. Administrators should verify and update all Office installations across x86, x64, macOS, and Android platforms (Microsoft MSRC, Tenable Blog).

Community reactions

CVE-2025-62557 was covered as part of broader December 2025 Patch Tuesday roundups by major security vendors and media outlets. Tenable, Qualys, Rapid7, CrowdStrike, and Sophos all included it in their Patch Tuesday analyses, noting it as a notable Office vulnerability requiring prompt patching (Tenable Blog, Qualys Blog, Rapid7). BleepingComputer and KrebsOnSecurity highlighted the December 2025 Patch Tuesday as a significant release addressing three zero-days and 57 flaws, with Office vulnerabilities receiving particular attention (BleepingComputer, KrebsOnSecurity). The Zero Day Initiative also reviewed the update, noting the breadth of Office-related fixes in December 2025 (ZDI Blog).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management