CVE-2025-62552

7.8

Microsoft · Office Access

A relative path traversal vulnerability in Microsoft Office Access allows an unauthorized attacker to execute arbitrary code locally.

Executive summary

A critical relative path traversal vulnerability in Microsoft Office Access permits local code execution, posing a significant risk to system integrity.

Vulnerability

The software is susceptible to a relative path traversal flaw (CWE-23) that allows an unauthenticated attacker to manipulate file paths and achieve local code execution. The attack vector is local (AV:L), requiring user interaction (UI:R) to trigger the malicious payload.

Business impact

This vulnerability carries a CVSS score of 7.8, which indicates a High severity level. Successful exploitation allows an attacker to execute code with the privileges of the victim, potentially leading to a complete compromise of the local machine, unauthorized access to sensitive data, and the installation of persistent threats within the corporate environment.

Remediation

Immediate Action: Apply the latest security updates provided by Microsoft via the official update guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62552.

Proactive Monitoring: Monitor system logs for unusual process execution patterns originating from Access or related Office components, particularly those involving unexpected file system paths.

Compensating Controls: Ensure that users operate with the principle of least privilege to limit the impact of potential code execution, and utilize endpoint protection software to detect and block suspicious file access attempts.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the High severity and the potential for local code execution, organizations must prioritize the deployment of the vendor-supplied patches across all affected versions of Microsoft Office. Administrators should ensure that automatic updates are enabled and verify that systems are compliant with the latest security baseline to mitigate the risk of exploitation.

More Microsoft CVEs

Sources