Microsoft Office 2016 vulnerabilities
161 known vulnerabilities affecting microsoft/microsoft_office_2016.
Total CVEs
161
CISA KEV
5
actively exploited
Public exploits
4
Exploited in wild
6
Severity breakdown
CRITICAL1HIGH124MEDIUM31LOW5
Vulnerabilities
Page 7 of 9
CVE-2025-24083P3HIGHCVSS 7.8≥ 16.0.0, < 16.0.5491.10012025-03-11
CVE-2025-24083 [HIGH] CWE-822 CVE-2025-24083: Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code lo
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-29792P3HIGHCVSS 7.3≥ 16.0.0, < 16.0.5495.10022025-04-08
CVE-2025-29792 [HIGH] CWE-416 CVE-2025-29792: Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-21346P3HIGHCVSS 7.8≥ 16.0.0, < 16.0.5483.10012025-01-14
CVE-2025-21346 [HIGH] CWE-693 CVE-2025-21346: Microsoft Office Security Feature Bypass Vulnerability
Microsoft Office Security Feature Bypass Vulnerability
nvd
CVE-2023-33149P3HIGHCVSS 7.8≥ 16.0.0, < 16.0.5404.10002023-07-11
CVE-2023-33149 [HIGH] CWE-416 CVE-2023-33149: Microsoft Office Graphics Remote Code Execution Vulnerability
Microsoft Office Graphics Remote Code Execution Vulnerability
nvd
CVE-2023-33152P3HIGHCVSS 7.8≥ 16.0.0, < 16.0.5404.10002023-07-11
CVE-2023-33152 [HIGH] CWE-122 CVE-2023-33152: Microsoft ActiveX Remote Code Execution Vulnerability
Microsoft ActiveX Remote Code Execution Vulnerability
nvd
CVE-2021-42293P3MEDIUMCVSS 6.5≥ 16.0.0, < 16.0.5254.10002021-12-15
CVE-2021-42293 [MEDIUM] CVE-2021-42293: Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerabilit
Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability
nvd
CVE-2026-20943P4HIGHCVSS 7.0≥ 16.0.0, < 16.0.5535.10002026-01-13
CVE-2026-20943 [HIGH] CWE-426 CVE-2026-20943: Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.
Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-21530P4MEDIUMCVSS 6.7≥ 16.0.0, < 16.0.5556.10002026-05-12
CVE-2026-21530 [MEDIUM] CWE-415 CVE-2026-21530: Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-49059P4HIGHCVSS 7.0≥ 16.0.0, < 16.0.5478.10042024-12-12
CVE-2024-49059 [HIGH] CWE-59 CVE-2024-49059: Microsoft Office Elevation of Privilege Vulnerability
Microsoft Office Elevation of Privilege Vulnerability
nvd
CVE-2021-31178P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.5161.10002021-05-11
CVE-2021-31178 [MEDIUM] CWE-191 CVE-2021-31178: Microsoft Office Information Disclosure Vulnerability
Microsoft Office Information Disclosure Vulnerability
nvd
CVE-2026-55026P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.5561.10002026-07-14
CVE-2026-55026 [MEDIUM] CWE-190 CVE-2026-55026: Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose infor
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-55057P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.5561.10002026-07-14
CVE-2026-55057 [MEDIUM] CWE-190 CVE-2026-55057: Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose infor
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-55042P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.5561.10002026-07-14
CVE-2026-55042 [MEDIUM] CWE-908 CVE-2026-55042: Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose inform
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-55027P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.5561.10002026-07-14
CVE-2026-55027 [MEDIUM] CWE-125 CVE-2026-55027: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-55023P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.5561.10002026-07-14
CVE-2026-55023 [MEDIUM] CWE-125 CVE-2026-55023: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-55047P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.5561.10002026-07-14
CVE-2026-55047 [MEDIUM] CWE-125 CVE-2026-55047: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-56195P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.5561.10002026-07-14
CVE-2026-56195 [MEDIUM] CWE-125 CVE-2026-56195: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-56192P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.5561.10002026-07-14
CVE-2026-56192 [MEDIUM] CWE-125 CVE-2026-56192: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-55028P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.5561.10002026-07-14
CVE-2026-55028 [MEDIUM] CWE-125 CVE-2026-55028: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2020-1497P4MEDIUMCVSS 5.5≥ 16.0.0, < publication2020-08-17
CVE-2020-1497 [MEDIUM] CVE-2020-1497: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the content
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data.
To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mu
nvd