Local Code Execution Vulnerability in Microsoft Outlook by Microsoft
CVE-2025-62562
7.8HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 9 December 2025
What is CVE-2025-62562?
A use-after-free vulnerability in Microsoft Outlook could potentially allow an unauthorized attacker to execute arbitrary code on the local system. This flaw arises from improper handling of memory during specific operations within the application, leading to a scenario where an attacker can leverage this vulnerability to manipulate the application’s memory and gain control over its execution flow.
Affected Version(s)
Microsoft 365 Apps for Enterprise 32-bit Systems 16.0.1
Microsoft Office 2019 32-bit Systems 19.0.0
Microsoft Office LTSC 2021 x64-based Systems 16.0.1