Microsoft disclosed and patched several remote code execution vulnerabilities affecting Microsoft Office, Word, and Outlook, including CVE-2025-49698, CVE-2025-49702, CVE-2025-54906, CVE-2025-62554, CVE-2025-62557, CVE-2025-62558, and CVE-2025-62562. The advisories identify repeated RCE issues across core productivity applications, with separate entries for Office-wide flaws as well as product-specific weaknesses in Word and Outlook.
The cluster of disclosures indicates a sustained stream of code-execution bugs in Microsoft’s document and messaging ecosystem, raising the risk of compromise through malicious files or email content handled by widely deployed enterprise software. Organizations using Microsoft 365 and on-premises Office components should prioritize the relevant security updates and verify patch coverage for Office, Word, and Outlook installations across user endpoints.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft published a Security Update Guide entry for CVE-2025-62555, identified as a Microsoft Word remote code execution vulnerability. The advisory marks the official disclosure or patch release for this additional December Office-related flaw.
Microsoft published Security Update Guide entries for CVE-2025-62554, CVE-2025-62557, CVE-2025-62558, and CVE-2025-62562, covering remote code execution vulnerabilities in Microsoft Office, Word, and Outlook. These entries reflect a coordinated December disclosure and update release for multiple related flaws.
Microsoft published a Security Update Guide entry for CVE-2025-54906, identified as a Microsoft Office remote code execution vulnerability. The advisory marks the official disclosure or patch release for this issue.
Microsoft published a Security Update Guide entry for CVE-2025-49703, identified as a Microsoft Word remote code execution vulnerability. The advisory reflects the official disclosure or patch release for this separate Office-related flaw.
Microsoft's Security Update Guide added advisories for CVE-2025-49702, a Microsoft Office remote code execution vulnerability, and CVE-2025-49698, a Microsoft Word remote code execution vulnerability. This indicates patches or official vulnerability disclosures were released on that date.
9 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.