Microsoft 365 Apps For Enterprise vulnerabilities
765 known vulnerabilities affecting microsoft/microsoft_365_apps_for_enterprise.
Total CVEs
765
CISA KEV
10
actively exploited
Public exploits
17
Exploited in wild
15
Severity breakdown
CRITICAL7HIGH584MEDIUM164LOW10
Vulnerabilities
Page 27 of 39
CVE-2023-28287P3HIGHCVSS 7.8≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2023-06-17
CVE-2023-28287 [HIGH] CWE-416 CVE-2023-28287: Microsoft Publisher Remote Code Execution Vulnerability
Microsoft Publisher Remote Code Execution Vulnerability
nvd
CVE-2023-24953P3HIGHCVSS 7.8≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2023-05-09
CVE-2023-24953 [HIGH] CWE-416 CVE-2023-24953: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2025-24083P3HIGHCVSS 7.8≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2025-03-11
CVE-2025-24083 [HIGH] CWE-822 CVE-2025-24083: Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code lo
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2023-33161P3HIGHCVSS 7.8≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2023-07-11
CVE-2023-33161 [HIGH] CWE-415 CVE-2023-33161: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2023-33158P3HIGHCVSS 7.8≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2023-07-11
CVE-2023-33158 [HIGH] CWE-191 CVE-2023-33158: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2024-38016P3HIGHCVSS 7.8≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2024-09-19
CVE-2024-38016 [HIGH] CWE-284 CVE-2024-38016: Microsoft Office Visio Remote Code Execution Vulnerability
Microsoft Office Visio Remote Code Execution Vulnerability
nvd
CVE-2025-21345P3HIGHCVSS 7.8≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2025-01-14
CVE-2025-21345 [HIGH] CWE-416 CVE-2025-21345: Microsoft Office Visio Remote Code Execution Vulnerability
Microsoft Office Visio Remote Code Execution Vulnerability
nvd
CVE-2025-30379P3HIGHCVSS 7.8≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2025-05-13
CVE-2025-30379 [HIGH] CWE-763 CVE-2025-30379: Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to
Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-30381P3HIGHCVSS 7.8≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2025-05-13
CVE-2025-30381 [HIGH] CWE-125 CVE-2025-30381: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-32705P3HIGHCVSS 7.8≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2025-05-13
CVE-2025-32705 [HIGH] CWE-125 CVE-2025-32705: Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code local
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.
nvd
CVE-2023-29335P3HIGHCVSS 7.5≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2023-05-09
CVE-2023-29335 [HIGH] CWE-20 CVE-2023-29335: Microsoft Word Security Feature Bypass Vulnerability
Microsoft Word Security Feature Bypass Vulnerability
nvd
CVE-2025-29792P3HIGHCVSS 7.3≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2025-04-08
CVE-2025-29792 [HIGH] CWE-416 CVE-2025-29792: Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-80087P3MEDIUMCVSS 6.5≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-80087 [MEDIUM] CWE-122 CVE-2026-80087: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to disclose informati
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2020-16934P3HIGHCVSS 7.8≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2020-10-16
CVE-2020-16934 [HIGH] CVE-2020-16934: <p>An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R
An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files. An attacker who successfully exploited the vulnerability could elevate privileges.
To exploit this vulnerability, an attacker would need to convince a user to open a specially crafted file.
The security update addresses the vulnerab
nvd
CVE-2020-16949P3HIGHCVSS 7.5≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2020-10-16
CVE-2020-16949 [HIGH] CWE-401 CVE-2020-16949: <p>A denial of service vulnerability exists in Microsoft Outlook software when the software fails to
A denial of service vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could cause a remote denial of service against a system.
Exploitation of the vulnerability requires that a specially crafted email be sent to a vulnerable Outlook
nvd
CVE-2023-36037P3HIGHCVSS 7.8≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2023-11-14
CVE-2023-36037 [HIGH] CVE-2023-36037: Microsoft Excel Security Feature Bypass Vulnerability
Microsoft Excel Security Feature Bypass Vulnerability
nvd
CVE-2022-37963P3HIGHCVSS 7.8≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2022-09-13
CVE-2022-37963 [HIGH] CVE-2022-37963: Microsoft Office Visio Remote Code Execution Vulnerability
Microsoft Office Visio Remote Code Execution Vulnerability
nvd
CVE-2021-42296P3HIGHCVSS 7.8≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2021-11-10
CVE-2021-42296 [HIGH] CWE-94 CVE-2021-42296: Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2023-35371P3HIGHCVSS 7.8≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2023-08-08
CVE-2023-35371 [HIGH] CWE-415 CVE-2023-35371: Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2023-35372P3HIGHCVSS 7.8≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2023-08-08
CVE-2023-35372 [HIGH] CWE-190 CVE-2023-35372: Microsoft Office Visio Remote Code Execution Vulnerability
Microsoft Office Visio Remote Code Execution Vulnerability
nvd