Microsoft Outlook Vulnerability Let Attackers Execute Malicious Code Remotely
Microsoft has addressed a critical remote code execution (RCE) vulnerability in Outlook, identified as CVE-2025-62562, which could enable attackers to execute malicious code on affected systems. This vulnerability, disclosed on December 9, 2025, requires…
Microsoft has addressed a critical remote code execution (RCE) vulnerability in Outlook, identified as CVE-2025-62562, which could enable attackers to execute malicious code on affected systems. This vulnerability, disclosed on December 9, 2025, requires prompt action from IT administrators and users.
The issue originates from a use-after-free weakness in Microsoft Office Outlook. Microsoft has classified this vulnerability as Important, with a CVSS score of 7.8.
The vulnerability requires local user interaction, where an attacker must persuade a user to engage with a malicious email to exploit the flaw. The exploitation process involves sending a specially crafted email that, when replied to, triggers the code execution chain. Notably, the Preview Pane is not an attack vector for this vulnerability.
This flaw affects multiple versions of Microsoft Office, including Microsoft Word 2016 (both 32-bit and 64-bit). The presence of the bug necessitates manual user interaction, which adds complexity to the attack but remains feasible through social engineering tactics.
This vulnerability, disclosed on December 9, 2025, requires prompt action from IT administrators and users.
Microsoft Word 2016 (32-bit & 64-bit) - Update Available (KB5002806) Microsoft Office LTSC 2024 (32-bit & 64-bit) - Update Available Microsoft Office LTSC 2021 (32-bit & 64-bit) - Update Available Microsoft Office 2019 (32-bit & 64-bit) - Update Available Microsoft 365 Apps for Enterprise (32-bit & 64-bit) - Update Available Microsoft SharePoint Server 2019 (All editions) - Update Available Microsoft SharePoint Enterprise Server 2016 (All editions) - Update Available Microsoft Office LTSC for Mac 2024 - Not yet available Microsoft Office LTSC for Mac 2021 - Not yet available
Security updates are accessible for most affected versions, with specific availability for Microsoft Word 2016 under build number 16.0.5530.1000. Microsoft has confirmed that security patches can be obtained through Windows Update and the Microsoft Download Center. Updates for Mac versions will be released as soon as possible.
Organizations are advised to prioritize the installation of available security updates across all impacted Microsoft Office versions. Administrators should deploy patches for both 32-bit and 64-bit editions according to their deployment protocols.
For systems without immediate patch availability, it is recommended to exercise caution with unsolicited emails and refrain from replying to suspicious messages.
The discovery and reporting of this vulnerability were credited to Haifei Li from EXPMON through coordinated disclosure. Currently, there is no evidence of active exploitation or public disclosure of exploit code.
Based on reporting by Cyber Security News.
