PatchSiren cyber security CVE debrief
CVE-2025-62199 Microsoft CVE debrief
CVE-2025-62199 is a Microsoft Office use-after-free vulnerability (CWE-416) publicly disclosed on 2025-11-11 and later modified on 2025-11-19. The official NVD record rates it HIGH (CVSS 7.8) with a local attack vector, no privileges required, but user interaction required; successful exploitation can impact confidentiality, integrity, and availability at a high level. The NVD CPE list indicates exposure across Microsoft 365 Apps enterprise, Excel 2016, Office for Android, and Office Long Term Servicing Channel 2021/2024 variants on x64, x86, and macOS. This makes the issue important for endpoint fleets that routinely open Office documents, even though no Known Exploited Vulnerabilities entry is included in the supplied data.
- Vendor
- Microsoft
- Product
- Office Long Term Servicing Channel
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-11-11
- Original CVE updated
- 2025-11-19
- Advisory published
- 2025-11-11
- Advisory updated
- 2025-11-19
Who should care
Endpoint and patch-management teams responsible for Microsoft Office deployments, especially Microsoft 365 Apps, Excel 2016, Office LTSC 2021/2024, and Office on Android/macOS. It is also relevant for organizations that frequently receive or open external Office files.
Technical summary
Microsoft describes the flaw as a use-after-free in Office. The published CVSS vector (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) means an attacker needs local access and user interaction, but no privileges. NVD maps the weakness to CWE-416 and lists affected Office-related CPEs across multiple product variants.
Defensive priority
High. Apply Microsoft updates promptly, verify whether your specific Office builds match the affected CPEs in the NVD record, and prioritize systems that handle untrusted documents or shared files.
Recommended defensive actions
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2025-62199.
- Inventory Office LTSC 2021/2024, Microsoft 365 Apps, Excel 2016, and Office on Android/macOS to confirm exposure.
- Prioritize patching workstations and VDI images used to open external or shared Office documents.
- Until patched, reduce exposure to untrusted Office files and attachments using existing organizational controls.
- Recheck Microsoft guidance after updates; the CVE was modified on 2025-11-19, so confirm the latest advisory details before closing the ticket.
Evidence notes
This debrief is based on the official CVE/NVD records and the Microsoft MSRC advisory link provided in the corpus. NVD lists CWE-416 and CVSS v3.1 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, and the CPE list includes Microsoft 365 Apps enterprise, Excel 2016, Office for Android, and Office LTSC 2021/2024 variants. No KEV entry was supplied, so exploitation in the wild is not asserted here.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-62199 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-62199
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-62199 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-62199
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62199
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://www.vicarius.io/vsociety/posts/cve-2025-62199-detect-microsoft-office-rce-vulnerability
af854a3a-2127-422b-91ae-364da2661108
-
Source reference
Unverified legacy reference
URL: https://www.vicarius.io/vsociety/posts/cve-2025-62199-mitigate-microsoft-office-rce-vulnerability
af854a3a-2127-422b-91ae-364da2661108
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.