
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62558 is a use-after-free vulnerability in Microsoft Office Word that allows an unauthorized attacker to execute arbitrary code locally. It was disclosed on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday security update cycle. Affected products include Microsoft Word 2016 (x86/x64), Microsoft Office 2019, Office LTSC 2021, Office LTSC 2024, Microsoft 365 Apps for Enterprise, Office for Mac 2021/2024, and Microsoft SharePoint Server 2016/2019. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).
The root cause is a use-after-free condition (CWE-416) in Microsoft Office Word's document processing logic, where memory that has been freed is subsequently accessed, enabling an attacker to control program execution flow. The attack vector is local, requiring user interaction — specifically, a victim must open a specially crafted malicious Word document. No privileges are required on the part of the attacker, but the exploit is constrained to local execution context, meaning the attacker must deliver the malicious document via phishing, email attachment, or other social engineering means. No public proof-of-concept code has been identified as of the disclosure date (Microsoft MSRC, BleepingComputer).
Successful exploitation allows an attacker to execute arbitrary code in the context of the logged-in user, resulting in high confidentiality, integrity, and availability impact. An attacker who achieves code execution could access or exfiltrate sensitive documents, install malware or backdoors, and potentially pivot to other systems on the network depending on the victim's privileges. The broad scope of affected products — spanning Word 2016 through Microsoft 365 Apps and SharePoint Server — means a large number of enterprise and consumer deployments are at risk (Microsoft MSRC, Feedly).
%TEMP%, %APPDATA%) following the opening of a Word document; suspicious .doc/.docx files received via email or downloaded from unknown sources.WINWORD.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe); unexpected network connections initiated by the Word process.WINWORD.EXE to unknown or suspicious external IP addresses or domains shortly after document opening.WINWORD.EXE; security logs recording new process creation events with WINWORD.EXE as the parent process for command-line utilities.Microsoft released patches for CVE-2025-62558 on December 9, 2025, as part of the December 2025 Patch Tuesday update. Affected users should apply the relevant security updates immediately: Word 2016 and SharePoint Server 2016 should be updated to build 16.0.5530.1000 or later; SharePoint Server 2019 to 16.0.10417.20075 or later; Microsoft 365 Apps, Office LTSC 2021/2024, and Office 2019 should be updated via the Office Security Releases channel (https://aka.ms/OfficeSecurityReleases). As interim mitigations, organizations should avoid opening Word documents from untrusted sources, disable macros in Office, and deploy endpoint detection and response (EDR) tools to monitor for suspicious WINWORD.EXE child process activity (Microsoft MSRC, Feedly).
The vulnerability was covered as part of broader December 2025 Patch Tuesday roundups by multiple security outlets. BleepingComputer noted it among 57 flaws fixed that month, with the update cycle also addressing three zero-days (BleepingComputer). The Zero Day Initiative (ZDI) included it in their December 2025 security update review (ZDI Blog). Sophos and Rapid7 also published Patch Tuesday analyses covering this vulnerability (Sophos, Rapid7). No significant controversy or unusual community reaction was noted beyond standard patch urgency advisories.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."