cbcvebase.

Microsoft Office 2016 vulnerabilities

161 known vulnerabilities affecting microsoft/microsoft_office_2016.

Total CVEs
161
CISA KEV
5
actively exploited
Public exploits
4
Exploited in wild
6
Severity breakdown
CRITICAL1HIGH124MEDIUM31LOW5

Vulnerabilities

Page 7 of 9
CVE-2025-24083P3HIGHCVSS 7.8≥ 16.0.0, < 16.0.5491.10012025-03-11
CVE-2025-24083 [HIGH] CWE-822 CVE-2025-24083: Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code lo Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-29792P3HIGHCVSS 7.3≥ 16.0.0, < 16.0.5495.10022025-04-08
CVE-2025-29792 [HIGH] CWE-416 CVE-2025-29792: Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-21346P3HIGHCVSS 7.8≥ 16.0.0, < 16.0.5483.10012025-01-14
CVE-2025-21346 [HIGH] CWE-693 CVE-2025-21346: Microsoft Office Security Feature Bypass Vulnerability Microsoft Office Security Feature Bypass Vulnerability
nvd
CVE-2023-33149P3HIGHCVSS 7.8≥ 16.0.0, < 16.0.5404.10002023-07-11
CVE-2023-33149 [HIGH] CWE-416 CVE-2023-33149: Microsoft Office Graphics Remote Code Execution Vulnerability Microsoft Office Graphics Remote Code Execution Vulnerability
nvd
CVE-2023-33152P3HIGHCVSS 7.8≥ 16.0.0, < 16.0.5404.10002023-07-11
CVE-2023-33152 [HIGH] CWE-122 CVE-2023-33152: Microsoft ActiveX Remote Code Execution Vulnerability Microsoft ActiveX Remote Code Execution Vulnerability
nvd
CVE-2021-42293P3MEDIUMCVSS 6.5≥ 16.0.0, < 16.0.5254.10002021-12-15
CVE-2021-42293 [MEDIUM] CVE-2021-42293: Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerabilit Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability
nvd
CVE-2026-20943P4HIGHCVSS 7.0≥ 16.0.0, < 16.0.5535.10002026-01-13
CVE-2026-20943 [HIGH] CWE-426 CVE-2026-20943: Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally. Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-21530P4MEDIUMCVSS 6.7≥ 16.0.0, < 16.0.5556.10002026-05-12
CVE-2026-21530 [MEDIUM] CWE-415 CVE-2026-21530: Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-49059P4HIGHCVSS 7.0≥ 16.0.0, < 16.0.5478.10042024-12-12
CVE-2024-49059 [HIGH] CWE-59 CVE-2024-49059: Microsoft Office Elevation of Privilege Vulnerability Microsoft Office Elevation of Privilege Vulnerability
nvd
CVE-2021-31178P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.5161.10002021-05-11
CVE-2021-31178 [MEDIUM] CWE-191 CVE-2021-31178: Microsoft Office Information Disclosure Vulnerability Microsoft Office Information Disclosure Vulnerability
nvd
CVE-2026-55026P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.5561.10002026-07-14
CVE-2026-55026 [MEDIUM] CWE-190 CVE-2026-55026: Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose infor Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-55057P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.5561.10002026-07-14
CVE-2026-55057 [MEDIUM] CWE-190 CVE-2026-55057: Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose infor Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-55042P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.5561.10002026-07-14
CVE-2026-55042 [MEDIUM] CWE-908 CVE-2026-55042: Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose inform Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-55027P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.5561.10002026-07-14
CVE-2026-55027 [MEDIUM] CWE-125 CVE-2026-55027: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-55023P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.5561.10002026-07-14
CVE-2026-55023 [MEDIUM] CWE-125 CVE-2026-55023: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-55047P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.5561.10002026-07-14
CVE-2026-55047 [MEDIUM] CWE-125 CVE-2026-55047: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-56195P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.5561.10002026-07-14
CVE-2026-56195 [MEDIUM] CWE-125 CVE-2026-56195: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-56192P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.5561.10002026-07-14
CVE-2026-56192 [MEDIUM] CWE-125 CVE-2026-56192: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-55028P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.5561.10002026-07-14
CVE-2026-55028 [MEDIUM] CWE-125 CVE-2026-55028: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2020-1497P4MEDIUMCVSS 5.5≥ 16.0.0, < publication2020-08-17
CVE-2020-1497 [MEDIUM] CVE-2020-1497: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the content An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mu
nvd
Microsoft Office 2016 vulnerabilities | cvebase