PatchSiren cyber security CVE debrief
CVE-2025-62557 Microsoft CVE debrief
CVE-2025-62557 is a high-severity use-after-free flaw in Microsoft Office that can allow an unauthorized attacker to execute code locally. NVD rates the issue 8.4/High and maps it to CWE-416. The record indicates affected Office families include Microsoft 365 Apps for enterprise, Office 2016, Office 2019, Office LTSC 2021, and Office LTSC 2024 across multiple platforms.
- Vendor
- Microsoft
- Product
- Microsoft 365 Apps for Enterprise
- CVSS
- HIGH 8.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-12-09
- Original CVE updated
- 2025-12-10
- Advisory published
- 2025-12-09
- Advisory updated
- 2025-12-10
Who should care
Administrators and security teams managing Microsoft Office deployments, especially fleets running Office LTSC, Microsoft 365 Apps for enterprise, or mixed Windows/macOS/Android Office installations. Endpoint teams should prioritize systems where untrusted local software or users can run.
Technical summary
The supplied NVD record describes a use-after-free condition in Microsoft Office that can be abused by an unauthorized local attacker to execute code. The CVSS vector is AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating high impact once local access conditions are met. NVD lists vulnerable CPEs for Microsoft 365 Apps for enterprise, Office 2016/2019, Office LTSC 2021/2024, and Office for Android. Microsoft’s advisory is referenced by NVD for vendor guidance.
Defensive priority
High — patch affected Microsoft Office installations promptly, with extra urgency on endpoints that allow untrusted local execution or that host sensitive data.
Recommended defensive actions
- Apply the Microsoft update referenced in the vendor advisory for CVE-2025-62557.
- Inventory Office deployments against the affected NVD CPE families, including Microsoft 365 Apps for enterprise and Office LTSC 2021/2024.
- Treat shared workstations and endpoints with broader local user access as higher priority for remediation.
- Monitor for unusual Office crashes or suspicious local execution activity on affected systems.
- Confirm remediation using Microsoft’s Security Update Guide entry for CVE-2025-62557.
Evidence notes
This debrief is based on the supplied NVD record and the Microsoft security advisory link referenced by NVD. The CVE description, CVSS vector, CWE-416 mapping, and affected CPE criteria are taken from the provided corpus. No exploit steps, reproduction details, or unsupported remediation specifics are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-62557 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-62557
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-62557 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-62557
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62557
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.