A high-severity use-after-free (UAF) vulnerability, tracked as CVE-2025-62557, has been identified in Microsoft Office's document parsing component. This flaw allows attackers to achieve local remote code execution (RCE) by tricking the application into parsing a specially crafted Office file, potentially granting the attacker code execution with the privileges of the affected process. The vulnerability is notable because it does not require prior privileges and leverages Office's widespread use as an initial access vector, especially through phishing and document-based attacks. Microsoft has released an advisory and patch as part of its December 2025 update rollup, and security experts recommend immediate remediation due to the high CVSS v3.1 base score of 8.4 and the risk of exploitation in enterprise environments.
The vulnerability is confirmed by both Microsoft's Security Response Center and independent vulnerability aggregators, which highlight the risk of memory corruption and the importance of verifying patch deployment across all affected Office SKUs. While there is some discrepancy in public reporting regarding the criticality label, the consensus is that this UAF bug poses a significant threat due to the ease of delivery and the potential for exploitation without macros or scripting. Organizations are urged to consult the official Microsoft advisory for precise patch information and to prioritize mitigation efforts to reduce exposure to this RCE vulnerability.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
As part of Microsoft's December 2025 Patch Tuesday updates, CVE-2025-62557 was included in the Office security update rollup, with remediation available through the relevant per-SKU KB/build updates. Coverage and guidance emphasized prompt patching, especially for systems and services that parse or preview Office documents.
Microsoft published CVE-2025-62557 on its Security Update Guide, describing a use-after-free vulnerability in Microsoft Office tracked as CWE-416 and rated high severity. The CVE entry lists a CVSS v3.1 score of 8.4 and indicates code execution impact, with no public proof-of-concept or confirmed in-the-wild exploitation noted at publication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.