
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62559 is a use-after-free vulnerability in Microsoft Office Word that allows an unauthorized attacker to execute arbitrary code locally. It was disclosed on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday security updates. Affected products include Microsoft Word 2016 (x86/x64), Microsoft Office 2019, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021 and 2024, Office for Mac 2021 and 2024, and Microsoft SharePoint Server 2016 and 2019. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).
The vulnerability is classified as CWE-416 (Use After Free), occurring within Microsoft Office Word's document processing logic. Exploitation requires a local attack vector with user interaction — specifically, a victim must open a maliciously crafted Word document, after which the use-after-free condition is triggered, enabling arbitrary code execution in the context of the current user. No elevated privileges are required by the attacker prior to exploitation. Community interest in reverse engineering the vulnerability has been noted on forums such as Reverse Engineering Stack Exchange and Tuts4You, suggesting researchers are actively analyzing the flaw (Microsoft MSRC, RE Stack Exchange).
Successful exploitation grants an attacker the ability to execute arbitrary code with the privileges of the logged-in user, resulting in high impact to confidentiality, integrity, and availability of the affected system. An attacker who achieves code execution could access sensitive documents, install malware, modify data, or use the compromised system as a pivot point for lateral movement within a network. The broad scope of affected products — spanning Word 2016 through Microsoft 365 Apps and SharePoint Server — means a large number of enterprise and consumer endpoints are potentially at risk (Microsoft MSRC).
WINWORD.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe) without user initiation.%TEMP%, %APPDATA%, or startup folders shortly after opening a Word document; new or modified scheduled tasks or registry run keys created by the Word process.WINWORD.EXE to external or unusual IP addresses, particularly after opening a document from an untrusted source.WINWORD.EXE as a parent process for unexpected child processes; application crash logs or Dr. Watson/WER reports referencing Word memory access violations around the time of exploitation.Microsoft released patches for CVE-2025-62559 as part of the December 9, 2025 Patch Tuesday update cycle. Affected users should apply the relevant security updates for their product: Microsoft Word 2016 (update to build 16.0.5530.1000 or later), SharePoint Server 2016 (16.0.5530.1000+), SharePoint Server 2019 (16.0.10417.20075+), and Microsoft 365 Apps / Office 2019 / LTSC 2021 / LTSC 2024 via the Office Security Releases channel (https://aka.ms/OfficeSecurityReleases). As interim mitigations, organizations should exercise caution when opening documents from untrusted sources, enable Protected View in Office settings, deploy updated antivirus and email filtering solutions, and consider disabling macros where not required (Microsoft MSRC).
The vulnerability was covered as part of broader December 2025 Patch Tuesday roundups by multiple security outlets. BleepingComputer noted the December 2025 update fixed 57 flaws including 3 zero-days, with CVE-2025-62559 among the notable Office vulnerabilities (BleepingComputer). Zero Day Initiative (ZDI) included it in their December 2025 security update review (ZDI Blog). Sophos and Rapid7 also published Patch Tuesday analyses covering this vulnerability. Community interest in reverse engineering the flaw was observed on Reverse Engineering Stack Exchange and Tuts4You forums, indicating researcher curiosity about the underlying memory corruption mechanism.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."