Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-software-vulnerabilityinitial-access-method

Microsoft Patches Multiple Office, Word, and Outlook RCE Flaws

Updated 29d agoFirst seen May 25, 20269 sources

Microsoft disclosed and patched several remote code execution vulnerabilities affecting Microsoft Office, Word, and Outlook, including CVE-2025-49698, CVE-2025-49702, CVE-2025-54906, CVE-2025-62554, CVE-2025-62557, CVE-2025-62558, and CVE-2025-62562. The advisories identify repeated RCE issues across core productivity applications, with separate entries for Office-wide flaws as well as product-specific weaknesses in Word and Outlook.

The cluster of disclosures indicates a sustained stream of code-execution bugs in Microsoft’s document and messaging ecosystem, raising the risk of compromise through malicious files or email content handled by widely deployed enterprise software. Organizations using Microsoft 365 and on-premises Office components should prioritize the relevant security updates and verify patch coverage for Office, Word, and Outlook installations across user endpoints.

Share:
Microsoft Patches Multiple Office, Word, and Outlook RCE Flaws
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Dec 9, 20257mo ago

Microsoft discloses CVE-2025-62555 in Word

Microsoft published a Security Update Guide entry for CVE-2025-62555, identified as a Microsoft Word remote code execution vulnerability. The advisory marks the official disclosure or patch release for this additional December Office-related flaw.

CVE-2025-62555 - Security Update Guide - Microsoft - Microsoft Word Remote Code Execution Vulnerability

Microsoft releases December advisories for Office, Word, and Outlook RCE flaws

Microsoft published Security Update Guide entries for CVE-2025-62554, CVE-2025-62557, CVE-2025-62558, and CVE-2025-62562, covering remote code execution vulnerabilities in Microsoft Office, Word, and Outlook. These entries reflect a coordinated December disclosure and update release for multiple related flaws.

Sep 9, 202510mo ago

Microsoft discloses CVE-2025-54906 in Office

Microsoft published a Security Update Guide entry for CVE-2025-54906, identified as a Microsoft Office remote code execution vulnerability. The advisory marks the official disclosure or patch release for this issue.

Jul 8, 20251y ago

Microsoft discloses CVE-2025-49703 in Word

Microsoft published a Security Update Guide entry for CVE-2025-49703, identified as a Microsoft Word remote code execution vulnerability. The advisory reflects the official disclosure or patch release for this separate Office-related flaw.

CVE-2025-49703 - Security Update Guide - Microsoft - Microsoft Word Remote Code Execution Vulnerability

Microsoft publishes fixes for CVE-2025-49702 and CVE-2025-49698

Microsoft's Security Update Guide added advisories for CVE-2025-49702, a Microsoft Office remote code execution vulnerability, and CVE-2025-49698, a Microsoft Word remote code execution vulnerability. This indicates patches or official vulnerability disclosures were released on that date.

SOURCE COVERAGE

Sources

9 references tracked. Mallory keeps watching after this page renders.

9 SOURCESView all
Msrc MicrosoftAdvisories
Dec 9, 2025

CVE-2025-62558 - Security Update Guide - Microsoft - Microsoft Word Remote Code Execution Vulnerability

msrc.microsoft.com

Open source
Msrc MicrosoftAdvisories
Dec 9, 2025

CVE-2025-62554 - Security Update Guide - Microsoft - Microsoft Office Remote Code Execution Vulnerability

msrc.microsoft.com

Open source
Msrc MicrosoftAdvisories
Dec 9, 2025

CVE-2025-62557 - Security Update Guide - Microsoft - Microsoft Office Remote Code Execution Vulnerability

msrc.microsoft.com

Open source
Msrc MicrosoftAdvisories
Dec 9, 2025

CVE-2025-62555 - Security Update Guide - Microsoft - Microsoft Word Remote Code Execution Vulnerability

msrc.microsoft.com

Open source
Msrc MicrosoftAdvisories
Dec 9, 2025

CVE-2025-62562 - Security Update Guide - Microsoft - Microsoft Outlook Remote Code Execution Vulnerability

msrc.microsoft.com

Open source
Msrc MicrosoftAdvisories
Sep 9, 2025

CVE-2025-54906 - Security Update Guide - Microsoft - Microsoft Office Remote Code Execution Vulnerability

msrc.microsoft.com

Open source
Msrc Product AdvisoriesAdvisories
Jul 8, 2025

CVE-2025-49698 - Security Update Guide - Microsoft - Microsoft Word Remote Code Execution Vulnerability

msrc.microsoft.com

Open source
Msrc MicrosoftAdvisories
Jul 8, 2025

CVE-2025-49703 - Security Update Guide - Microsoft - Microsoft Word Remote Code Execution Vulnerability

msrc.microsoft.com

Open source
Msrc Product AdvisoriesAdvisories
Jul 8, 2025

CVE-2025-49702 - Security Update Guide - Microsoft - Microsoft Office Remote Code Execution Vulnerability

msrc.microsoft.com

Open source
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Microsoft Patches Multiple Office, Word, and Outlook RCE Flaws | Mallory