CVE-2025-62554Patch(microsoft / 365_apps)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft 365_apps systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-843

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_apps
  • 365_copilot
  • office
  • office_long_term_servicing_channel

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-01-28); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
365_apps365_copilotofficeoffice_long_term_servicing_channel

5 versions affected across 4 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-01-28: 1Mentions · 2026-10-08: 1PoC Mentioned / Linked · 2026-01-28: 1Patch / Workaround · 2026-01-28: 1Technical Details · 2026-01-28: 101-2810-08
Signal classification1 categories
Patch
1100.0%
Full discourse2 posts
  • DFIR Lab@DFIR_Lab

    🚨 HIGH SEVERITY: CVE-2025-62554 (CVSS 8.4) Type confusion vulnerability in Microsoft Office enables unauthorized local code execution. No user interaction required. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/0f0ZWzO70X

    0000030
    145 followersView on X
  • Ostorlab@OstorlabSec
    Patch

    🚨 CVE-2025-62554 : CRITICAL MICROSOFT OFFICE RCE ALERT 🚨 @Microsoft  A type confusion remote code execution vulnerability has been disclosed in Microsoft Office — the world’s most widely deployed enterprise productivity suite. Risk Severity: Critical (trending, ransomware-relevant, public PoC available) Impact: • Arbitrary code execution via malicious documents • Full compromise of user endpoints • Credential theft & lateral movement • Persistent access via Office add-ins/templates • Common initial access vector for ransomware & APTs Root Cause: CWE-843 (Type Confusion) Microsoft Office improperly validates embedded OLE object types. Malformed documents exploit incompatible object casting, corrupting memory and hijacking execution flow when Office parses document content. Attackers can: • Deliver malicious .docx, .xlsx, or .pptx files via phishing • Trigger memory corruption during OLE object parsing • Achieve code execution in winword.exe, excel.exe, or powerpnt.exe • Run payloads with victim user privileges • Pivot laterally across network shares and mapped drives Are You Affected? Vulnerable: • Office 2016 • Office 2019 • Microsoft 365 Apps (pre–Jan 2026 updates) Platforms: Windows & macOS Immediate Action Required: Update: Deploy January 2026 Office security updates immediately Mitigation: Quarantine external Office attachments; enable ASR rules blocking Office child processes Audit: Hunt for Office spawning PowerShell, rundll32, or executables from %TEMP% Office documents remain a Tier-0 ransomware delivery vector. Patch, restrict, and monitor aggressively. 🛡️ #microsoft #security #ostorlabCVE

    Post summary

    The post announces the critical Microsoft Office RCE CVE‑2025‑62554, details its technical aspects, and urges users to apply the January 2026 patch and other mitigations immediately.

    0000092
    581 followersView on X
CPE platform detail13 entries

13 of 13 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_apps--x64
Appmicrosoft365_apps--x86
Appmicrosoft365_copilot-android-
Appmicrosoftoffice2016-x64
Appmicrosoftoffice2016-x86
Appmicrosoftoffice2019-x64
Appmicrosoftoffice2019-x86
Appmicrosoftoffice_long_term_servicing_channel2021-x64
Appmicrosoftoffice_long_term_servicing_channel2021-x86
Appmicrosoftoffice_long_term_servicing_channel2021macos-
Appmicrosoftoffice_long_term_servicing_channel2024-x64
Appmicrosoftoffice_long_term_servicing_channel2024-x86
Appmicrosoftoffice_long_term_servicing_channel2024macos-

Explore more