CVE-2025-62558
vulnerability analysis and mitigation

Overview

CVE-2025-62558 is a use-after-free vulnerability in Microsoft Office Word that allows an unauthorized attacker to execute arbitrary code locally. It was disclosed on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday security update cycle. Affected products include Microsoft Word 2016 (x86/x64), Microsoft Office 2019, Office LTSC 2021, Office LTSC 2024, Microsoft 365 Apps for Enterprise, Office for Mac 2021/2024, and Microsoft SharePoint Server 2016/2019. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).

Technical details

The root cause is a use-after-free condition (CWE-416) in Microsoft Office Word's document processing logic, where memory that has been freed is subsequently accessed, enabling an attacker to control program execution flow. The attack vector is local, requiring user interaction — specifically, a victim must open a specially crafted malicious Word document. No privileges are required on the part of the attacker, but the exploit is constrained to local execution context, meaning the attacker must deliver the malicious document via phishing, email attachment, or other social engineering means. No public proof-of-concept code has been identified as of the disclosure date (Microsoft MSRC, BleepingComputer).

Impact

Successful exploitation allows an attacker to execute arbitrary code in the context of the logged-in user, resulting in high confidentiality, integrity, and availability impact. An attacker who achieves code execution could access or exfiltrate sensitive documents, install malware or backdoors, and potentially pivot to other systems on the network depending on the victim's privileges. The broad scope of affected products — spanning Word 2016 through Microsoft 365 Apps and SharePoint Server — means a large number of enterprise and consumer deployments are at risk (Microsoft MSRC, Feedly).

Exploitation steps

  1. Craft malicious document: An attacker creates a specially crafted Microsoft Word document (.doc/.docx) that triggers the use-after-free condition in Word's document processing engine upon opening.
  2. Deliver the document: The attacker delivers the malicious file to the target via phishing email, malicious download link, or other social engineering vector.
  3. Victim opens the document: The target user opens the file in a vulnerable version of Microsoft Word (e.g., Word 2016, Office 2019, Microsoft 365 Apps).
  4. Trigger use-after-free: Opening the document triggers the memory corruption bug — a freed memory region is accessed, allowing the attacker to control execution flow.
  5. Achieve code execution: The attacker's shellcode or payload executes in the context of the victim user, enabling installation of malware, credential theft, or further lateral movement within the network (Microsoft MSRC, Feedly).

Indicators of compromise

  • File System: Unexpected or newly created executable files, scripts, or DLLs in user temp directories (e.g., %TEMP%, %APPDATA%) following the opening of a Word document; suspicious .doc/.docx files received via email or downloaded from unknown sources.
  • Process: Unusual child processes spawned by WINWORD.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe); unexpected network connections initiated by the Word process.
  • Network: Outbound connections from WINWORD.EXE to unknown or suspicious external IP addresses or domains shortly after document opening.
  • Logs: Windows Event Logs showing application crashes or abnormal termination of WINWORD.EXE; security logs recording new process creation events with WINWORD.EXE as the parent process for command-line utilities.

Mitigation and workarounds

Microsoft released patches for CVE-2025-62558 on December 9, 2025, as part of the December 2025 Patch Tuesday update. Affected users should apply the relevant security updates immediately: Word 2016 and SharePoint Server 2016 should be updated to build 16.0.5530.1000 or later; SharePoint Server 2019 to 16.0.10417.20075 or later; Microsoft 365 Apps, Office LTSC 2021/2024, and Office 2019 should be updated via the Office Security Releases channel (https://aka.ms/OfficeSecurityReleases). As interim mitigations, organizations should avoid opening Word documents from untrusted sources, disable macros in Office, and deploy endpoint detection and response (EDR) tools to monitor for suspicious WINWORD.EXE child process activity (Microsoft MSRC, Feedly).

Community reactions

The vulnerability was covered as part of broader December 2025 Patch Tuesday roundups by multiple security outlets. BleepingComputer noted it among 57 flaws fixed that month, with the update cycle also addressing three zero-days (BleepingComputer). The Zero Day Initiative (ZDI) included it in their December 2025 security update review (ZDI Blog). Sophos and Rapid7 also published Patch Tuesday analyses covering this vulnerability (Sophos, Rapid7). No significant controversy or unusual community reaction was noted beyond standard patch urgency advisories.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management