CVE-2025-62205
7.8Microsoft · Office Word
A use after free vulnerability in Microsoft Office Word allows an attacker to execute arbitrary code locally through memory corruption.
Executive summary
A critical use after free vulnerability in Microsoft Office Word could allow an unauthorized local attacker to achieve code execution.
Vulnerability
This is a use after free flaw (CWE-416) within Microsoft Office Word. An attacker can trigger this vulnerability to achieve local code execution, though it requires user interaction as indicated by the CVSS vector.
Business impact
Successful exploitation of this vulnerability permits an attacker to execute arbitrary code with the privileges of the logged in user. Given the CVSS score of 7.8, this represents a high risk to organizational security, potentially leading to full system compromise, data exfiltration, or the installation of persistent malware within the enterprise environment.
Remediation
Immediate Action: Administrators must apply the latest security updates released by Microsoft via the official update guide at https://aka.ms/OfficeSecurityReleases.
Proactive Monitoring: Security teams should monitor endpoint activity for suspicious child processes spawned by Winword.exe and review logs for unexpected file system modifications.
Compensating Controls: Ensure that Attack Surface Reduction (ASR) rules are enabled to prevent Office applications from creating child processes and restrict the execution of macros from untrusted sources.
Exploitation status
Public Exploit Available: No — exploit_available (false).
Analyst recommendation
This vulnerability presents a significant risk to workstations and server environments utilizing Microsoft Office. Organizations should prioritize the deployment of the vendor provided security updates across all affected Office installations to neutralize the memory corruption risk, as local code execution remains a high priority threat vector for enterprise security.
More Microsoft CVEs
Sources
- Microsoft Office Remote Code Execution Vulnerability Vendor advisory