CVE-2025-62554

HIGH

Microsoft 365 Apps - Type Confusion

Title source: rule
STIX 2.1

Description

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Scores

CVSS v3 8.4
EPSS 0.0026
EPSS Percentile 49.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-843
Status published
Products (14)
microsoft/365_apps (2 CPE variants)
Microsoft/Microsoft 365 Apps for Enterprise 16.0.1 - https://aka.ms/OfficeSecurityReleases
Microsoft/Microsoft Office 2016 16.0.0 - 16.0.5530.1001
Microsoft/Microsoft Office 2019 19.0.0 - https://aka.ms/OfficeSecurityReleases
Microsoft/Microsoft Office for Android 16.0.1 - 16.0.19530.20000
Microsoft/Microsoft Office LTSC 2021 16.0.1 - https://aka.ms/OfficeSecurityReleases
Microsoft/Microsoft Office LTSC 2024 16.0.0 - https://aka.ms/OfficeSecurityReleases
Microsoft/Microsoft Office LTSC for Mac 2021 16.0.1 - 16.104.25121423
Microsoft/Microsoft Office LTSC for Mac 2024 16.0.0 - 16.104.25121423
microsoft/office
... and 4 more
Published Dec 09, 2025
Tracked Since Feb 18, 2026