Executive brief
A security vulnerability in Microsoft Office could allow an attacker to run malicious code on a user's computer. This typically occurs if a user is tricked into opening a specially crafted file. If successful, the attacker could gain the same permissions as the user, potentially leading to data theft or unauthorized system changes.
Technical details
A use-after-free (UAF) vulnerability exists in multiple Microsoft Office products, including Excel 2016, Office LTSC, and Microsoft 365 Apps. The flaw is triggered when the application continues to use a memory pointer after it has been freed, which can be exploited to achieve arbitrary code execution. The attack vector is local, requiring a user to open a malicious file (User Interaction: Required). The vulnerability has been addressed in security updates, such as version 16.0.19426.20044 for Android and corresponding patches for desktop platforms.
Affected products
- Microsoft Office Android versions prior to 16.0.19426.20044; Office 2016; Office LTSC 2021/2024; Microsoft 365 Apps
Timeline
- 2025-11-11: disclosed: Initial publication of CVE-2025-62199 by Microsoft
- 2025-11-11: advisory: Microsoft released the security update guide for this vulnerability