cbcvebase.

Microsoft Access vulnerabilities

37 known vulnerabilities affecting microsoft/access.

Total CVEs
37
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL10HIGH27

Vulnerabilities

Page 2 of 2
CVE-2026-64906P3HIGHCVSS 7.8v20162026-08-11
CVE-2026-64906 [HIGH] CWE-122 CVE-2026-64906: Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute cod Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-62552P3HIGHCVSS 7.8v20162025-12-09
CVE-2025-62552 [HIGH] CWE-23 CVE-2025-62552: Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code l Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-26630P3HIGHCVSS 7.8v20162025-03-11
CVE-2025-26630 [HIGH] CWE-416 CVE-2025-26630: Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-69477P3HIGHCVSS 7.3v20162026-09-08
CVE-2026-69477 [HIGH] CWE-122 CVE-2026-69477: Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally.
nvd
CVE-2006-3877P3CRITICALCVSS 9.3v2000v2002+1 more2006-10-10
CVE-2006-3877 [CRITICAL] CVE-2006-3877: Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2 Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876.
nvd
CVE-2020-1582P3HIGHCVSS 7.8v2010v2013+1 more2020-08-17
CVE-2020-1582 [HIGH] CVE-2020-1582: A remote code execution vulnerability exists in Microsoft Access software when the software fails to A remote code execution vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affec
nvd
CVE-2025-21186P3HIGHCVSS 7.8v20162025-01-14
CVE-2025-21186 [HIGH] CWE-122 CVE-2025-21186: Microsoft Access Remote Code Execution Vulnerability Microsoft Access Remote Code Execution Vulnerability
nvd
CVE-2025-21366P3HIGHCVSS 7.8v20162025-01-14
CVE-2025-21366 [HIGH] CWE-416 CVE-2025-21366: Microsoft Access Remote Code Execution Vulnerability Microsoft Access Remote Code Execution Vulnerability
nvd
CVE-2024-49142P3HIGHCVSS 7.8v20162024-12-12
CVE-2024-49142 [HIGH] CWE-416 CVE-2024-49142: Microsoft Access Remote Code Execution Vulnerability Microsoft Access Remote Code Execution Vulnerability
nvd
CVE-2025-21395P3HIGHCVSS 7.8v20162025-01-14
CVE-2025-21395 [HIGH] CWE-122 CVE-2025-21395: Microsoft Access Remote Code Execution Vulnerability Microsoft Access Remote Code Execution Vulnerability
nvd
CVE-2025-26642P3HIGHCVSS 7.8v20162025-04-08
CVE-2025-26642 [HIGH] CWE-125 CVE-2025-26642: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2008-1200P3CRITICALCVSS 9.3v20002008-03-06
CVE-2008-1200 [CRITICAL] CVE-2008-1200: Unspecified vulnerability in Microsoft Access allows remote user-assisted attackers to execute arbit Unspecified vulnerability in Microsoft Access allows remote user-assisted attackers to execute arbitrary code via a crafted .MDB file, possibly related to Jet Engine (msjet40.dll). NOTE: this is probably a different issue than CVE-2007-6026.
nvd
CVE-2000-0788P3CRITICALCVSS 10.0v20002000-10-20
CVE-2000-0788 [CRITICAL] CVE-2000-0788: The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) s The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow an attacker to execute arbitrary commands.
nvd
CVE-1999-0364P3CRITICALCVSS 10.0v971999-01-01
CVE-1999-0364 [CRITICAL] CVE-1999-0364: Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to dat Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.
nvd
CVE-2000-0419P4HIGHCVSS 7.5v20002000-05-11
CVE-2000-0419 [HIGH] CVE-2000-0419: The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerability.
nvd
CVE-2025-59235P4HIGHCVSS 7.1v20162025-10-14
CVE-2025-59235 [HIGH] CWE-125 CVE-2025-59235: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2025-59232P4HIGHCVSS 7.1v20162025-10-14
CVE-2025-59232 [HIGH] CWE-125 CVE-2025-59232: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
Microsoft Access vulnerabilities | cvebase