
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62563 is a use-after-free vulnerability in Microsoft Office Excel that allows an unauthorized attacker to execute arbitrary code locally. It was disclosed on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday security update. Affected products include Microsoft Excel 2016 (x86/x64), Microsoft Office 2019, Office 2021, Office 2024, Office LTSC 2021 and 2024 (Windows and macOS), Microsoft 365 Apps for Enterprise, and Office Online Server (versions prior to 16.0.10417.20075). The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (MSRC).
The vulnerability is classified as CWE-416 (Use After Free), occurring within Microsoft Excel's document processing logic. Exploitation requires a user to open a specially crafted malicious Excel file, after which the use-after-free condition is triggered, enabling arbitrary code execution in the context of the current user. The attack vector is local (the file must be opened on the victim's machine), requires no privileges, but does require user interaction — consistent with a social engineering or phishing delivery mechanism. No public proof-of-concept or detailed technical write-up has been identified at this time (MSRC, ZDI Blog).
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the logged-in user, resulting in high confidentiality, integrity, and availability impact. An attacker could access sensitive data, modify or delete files, install malware, or potentially pivot to other systems if the compromised user account has elevated permissions or network access. The scope is limited to the affected system (unchanged scope), but the combination of full CIA triad compromise makes this a significant risk in enterprise environments where Excel is widely deployed (MSRC).
%TEMP%, %APPDATA%) shortly after opening an Excel document.EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe); Excel process making unexpected outbound network connections.EXCEL.EXE to unknown or suspicious IP addresses or domains; DNS queries for unusual domains initiated by the Office process.EXCEL.EXE (Event ID 1000/1001); security logs recording new process creation with EXCEL.EXE as parent process for command-line utilities.Microsoft released patches for all affected products as part of the December 9, 2025 Patch Tuesday update. Users should apply the relevant security updates immediately: Excel 2016 should be updated to build 16.0.5530.1000 or later; Office Online Server should be updated to 16.0.10417.20075 or later; Microsoft 365 Apps, Office 2019, 2021, and 2024 should be updated via the Office Security Releases channel (https://aka.ms/OfficeSecurityReleases). As interim mitigations, organizations should restrict opening Excel files from untrusted sources, implement email attachment filtering, and consider enabling Protected View or Application Guard for Office to sandbox untrusted documents (MSRC, Sophos).
The December 2025 Patch Tuesday was broadly covered by security media, with primary attention focused on the three zero-day vulnerabilities patched that month; CVE-2025-62563 received standard coverage as part of the broader Excel vulnerability set. Sophos noted it was a "big finish to 2025" for Patch Tuesday, and Zero Day Initiative reviewed the update batch including this flaw. BleepingComputer and CyberSecurityNews covered the overall release, noting 57 vulnerabilities fixed. No specific researcher commentary or notable social media discussion was identified for this individual CVE (BleepingComputer, ZDI Blog, Sophos).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."