
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62562 is a use-after-free (UAF) vulnerability in Microsoft Office Outlook that allows an unauthorized local attacker to execute arbitrary code on affected systems. Disclosed on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday, the vulnerability requires user interaction to trigger. Affected products include Microsoft 365 Apps for Enterprise, Office 2019, Office 2021 (LTSC), Office 2024 (LTSC), Office for Mac 2021/2024, Word 2016, and SharePoint Server 2016/2019. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).
The vulnerability is classified as CWE-416 (Use After Free), meaning Outlook accesses memory that has already been freed, potentially allowing an attacker to control program execution flow. The attack vector is local (AV:L), requires no privileges (PR:N), but does require user interaction (UI:R) — likely involving a user opening or previewing a malicious file or email. The scope is unchanged, indicating the impact is confined to the vulnerable component. No public proof-of-concept or detailed technical write-up has been published as of the disclosure date (Microsoft MSRC, Feedly).
Successful exploitation could allow an attacker to execute arbitrary code with the privileges of the local user running Outlook, resulting in high confidentiality, integrity, and availability impact. This could lead to unauthorized system access, data theft, installation of malware, or complete compromise of the affected system. While the attack vector is local and requires user interaction, the breadth of affected Office products — spanning enterprise deployments across Windows and macOS — makes the potential organizational impact significant (Microsoft MSRC, Feedly).
Microsoft released patches on December 9, 2025, addressing this vulnerability across all affected products. Specific fixed versions include Microsoft Word 2016 updated to build 16.0.5530.1000 or later, and SharePoint Server 2016/2019 updated to build 16.0.5530.1000 / 16.0.10417.20075 or later; Microsoft 365 Apps, Office 2019/2021/2024 should be updated via the Office Security Releases channel (Microsoft MSRC). Organizations should apply the December 2025 cumulative updates immediately, enforce least-privilege principles for local user accounts, and deploy endpoint detection and response (EDR) tools to monitor for anomalous Outlook process behavior. No configuration-based workaround has been published by Microsoft.
The December 2025 Patch Tuesday was broadly covered by security media, with outlets such as BleepingComputer, Krebs on Security, and Cisco Talos highlighting the overall release of 57 fixes including 3 zero-days, though CVE-2025-62562 was not among the zero-days (BleepingComputer, Krebs on Security, Talos Intelligence). The Zero Day Initiative noted the vulnerability in their December 2025 security update review (ZDI). Community discussion on forums such as WindowsForum.com emphasized the importance of applying all applicable updates given the RCE potential in Outlook (WindowsForum). Sophos and Qualys also included the vulnerability in their Patch Tuesday analysis blogs (Sophos, Qualys Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."