Microsoft Office vulnerabilities
85 known vulnerabilities affecting microsoft/microsoft_office.
Total CVEs
85
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
4
Severity breakdown
CRITICAL3HIGH54MEDIUM28
Vulnerabilities
Page 2 of 5
CVE-2018-8587P3HIGHCVSS 7.8v2019 for 32-bit editionsv2019 for 64-bit editions2018-12-12
CVE-2018-8587 [HIGH] CVE-2018-8587: A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly
A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook.
nvd
CVE-2019-1448P3HIGHCVSS 7.8v2016 for Macv2019 for 32-bit editions+2 more2019-11-12
CVE-2019-1448 [HIGH] CVE-2019-1448: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
nvd
CVE-2020-0760P3HIGHCVSS 8.8v2019 for 32-bit editionsv2019 for 64-bit editions+7 more2020-04-15
CVE-2020-0760 [HIGH] CVE-2020-0760: A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type l
A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0991.
nvd
CVE-2018-8430P3HIGHCVSS 7.8v2016 Click-to-Run (C2R) for 32-bit editionsv2016 Click-to-Run (C2R) for 64-bit editions2018-09-13
CVE-2018-8430 [HIGH] CVE-2018-8430: A remote code execution vulnerability exists in Microsoft Word if a user opens a specially crafted P
A remote code execution vulnerability exists in Microsoft Word if a user opens a specially crafted PDF file, aka "Word PDF Remote Code Execution Vulnerability." This affects Microsoft Word, Microsoft Office.
nvd
CVE-2020-1349P3HIGHCVSS 7.8v2019 for 32-bit editionsv2019 for 64-bit editions2020-07-14
CVE-2020-1349 [HIGH] CVE-2020-1349: A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly
A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka 'Microsoft Outlook Remote Code Execution Vulnerability'.
nvd
CVE-2018-8248P3HIGHCVSS 7.8v2010 Service Pack 2 (32-bit editions)v2010 Service Pack 2 (64-bit editions)+7 more2018-06-14
CVE-2018-8248 [HIGH] CVE-2018-8248: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office.
nvd
CVE-2018-8331P3HIGHCVSS 7.8v2016 Click-to-Run (C2R) for 32-bit editionsv2016 Click-to-Run (C2R) for 64-bit editions+1 more2018-09-13
CVE-2018-8331 [HIGH] CVE-2018-8331: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office.
nvd
CVE-2018-8147P3HIGHCVSS 7.8v2016 Click-to-Run (C2R) for 32-bit editionsv2016 Click-to-Run (C2R) for 64-bit editions2018-05-09
CVE-2018-8147 [HIGH] CVE-2018-8147: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-8148, CVE-2018-8162.
nvd
CVE-2018-8157P3HIGHCVSS 7.8v2010 Service Pack 2 (32-bit editions)v2010 Service Pack 2 (64-bit editions)+2 more2018-05-09
CVE-2018-8157 [HIGH] CVE-2018-8157: A remote code execution vulnerability exists in Microsoft Office software when the software fails to
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-8158, CVE-2018-8161.
nvd
CVE-2019-1462P3HIGHCVSS 7.8v2019 for 32-bit editionsv2019 for 64-bit editions+2 more2019-12-10
CVE-2019-1462 [HIGH] CWE-908 CVE-2019-1462: A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fail
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka 'Microsoft PowerPoint Remote Code Execution Vulnerability'.
nvd
CVE-2020-0850P3HIGHCVSS 8.8v2019 for 32-bit editionsv2019 for 64-bit editions+4 more2020-03-12
CVE-2020-0850 [HIGH] CVE-2020-0850: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0851, CVE-2020-0852, CVE-2020-0855, CVE-2020-0892.
nvd
CVE-2018-8281P3HIGHCVSS 7.8v2016 Click-to-Run (C2R) for 32-bit editionsv2016 Click-to-Run (C2R) for 64-bit editions+2 more2018-07-11
CVE-2018-8281 [HIGH] CVE-2018-8281: A remote code execution vulnerability exists in Microsoft Office software when the software fails to
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Excel Viewer, Microsoft PowerPoint Viewer, Microsoft Office, Microsoft Office Word Viewer.
nvd
CVE-2018-8312P3HIGHCVSS 7.8v2016 Click-to-Run (C2R) for 32-bit editionsv2016 Click-to-Run (C2R) for 64-bit editions2018-07-11
CVE-2018-8312 [HIGH] CVE-2018-8312: A remote code execution vulnerability exists when Microsoft Access fails to properly handle objects
A remote code execution vulnerability exists when Microsoft Access fails to properly handle objects in memory, aka "Microsoft Access Remote Code Execution Vulnerability." This affects Microsoft Access, Microsoft Office.
nvd
CVE-2019-1109P3CRITICALCVSS 9.1v2013 Service Pack 1 (32-bit editions)v2013 Service Pack 1 (64-bit editions)+5 more2019-07-15
CVE-2019-1109 [CRITICAL] CWE-20 CVE-2019-1109: A spoofing vulnerability exists when Microsoft Office Javascript does not check the validity of the
A spoofing vulnerability exists when Microsoft Office Javascript does not check the validity of the web page making a request to Office documents.An attacker who successfully exploited this vulnerability could read or write information in Office documents.The security update addresses the vulnerability by correcting the way that Microsoft Office Javas
nvd
CVE-2019-0801P3HIGHCVSS 7.8v2010 Service Pack 2 (32-bit editions)v2010 Service Pack 2 (64-bit editions)+7 more2019-04-09
CVE-2019-0801 [HIGH] CWE-19 CVE-2019-0801: A remote code execution vulnerability exists when Microsoft Office fails to properly handle certain
A remote code execution vulnerability exists when Microsoft Office fails to properly handle certain files.To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file that points to an Excel or PowerPoint file that was also downloaded.The update addresses the vulnerability by correcting how Office handles th
nvd
CVE-2018-8628P3HIGHCVSS 7.8v2016 for Macv2019 for 32-bit editions+5 more2018-12-12
CVE-2018-8628 [HIGH] CVE-2018-8628: A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fail
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft PowerPoint, Microsoft SharePoint, Microsoft PowerPoint Viewer, Office Online Server, Microsoft Sha
nvd
CVE-2018-0920P3HIGHCVSS 7.8v2016 for MacvCompatibility Pack Service Pack 32018-04-12
CVE-2018-0920 [HIGH] CVE-2018-0920: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Excel. This CVE ID is unique from CVE-2018-1011, CVE-2018-1027, CVE-2018-1029.
nvd
CVE-2018-8522P3HIGHCVSS 7.8v2019 for 32-bit editionsv2019 for 64-bit editions2018-11-14
CVE-2018-8522 [HIGH] CVE-2018-8522: A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly
A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. This CVE ID is unique from CVE-2018-8524, CVE-2018-8576, CVE-2018-8582.
nvd
CVE-2018-8574P3HIGHCVSS 7.8v2010 Service Pack 2 (32-bit editions)v2010 Service Pack 2 (64-bit editions)+11 more2018-11-14
CVE-2018-8574 [HIGH] CVE-2018-8574: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-8577.
nvd
CVE-2018-8539P3HIGHCVSS 7.8v2010 Service Pack 2 (32-bit editions)v2010 Service Pack 2 (64-bit editions)+2 more2018-11-14
CVE-2018-8539 [HIGH] CVE-2018-8539: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Microsoft SharePoint Server, Microsoft Office. This CVE ID is unique from CVE-2018-8573.
nvd