Junglewise Threat Intelligence

CVE-2025-62557: Microsoft Office use after free local code execution

CVE-2025-62557 · Severity: high · CVSS 8.4 · Published 2025-12-09

Technologies: Microsoft Office LTSC 2024, Microsoft Office for Android, Microsoft Office LTSC 2021, Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A vulnerability in Microsoft Office could allow an attacker to run malicious code on a user's computer. Microsoft Office is a widely used suite of productivity applications including Word, Excel, and PowerPoint. If exploited, this flaw could allow an unauthorized person to gain full control over the affected system, potentially leading to data theft or further network compromise.

Technical details

A use-after-free (UAF) vulnerability exists in Microsoft Office (CWE-416). The flaw is triggered when the application continues to use a pointer after it has been freed, leading to memory corruption. An attacker with local access to the system can exploit this to execute arbitrary code with the privileges of the logged-in user. The vulnerability affects multiple versions of Office across Windows, macOS, and Android, including Office 2016, 2019, LTSC 2021/2024, and Microsoft 365 Apps. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Office 2016 x86 and x64 editions
  • Microsoft Office 2019 x86 and x64 editions
  • Microsoft Office LTSC 2021 Windows and macOS
  • Microsoft Office LTSC 2024 Windows and macOS
  • Microsoft 365 Apps for Enterprise x86 and x64 editions
  • Microsoft Office for Android
  • Microsoft 365 Copilot for Android

Timeline

  • 2025-12-09: disclosed: Initial disclosure by Microsoft
  • 2025-12-09: advisory: Microsoft Security Update Guide published

References

Related threats