Microsoft Office 2019 vulnerabilities
696 known vulnerabilities affecting microsoft/microsoft_office_2019.
Total CVEs
696
CISA KEV
9
actively exploited
Public exploits
13
Exploited in wild
12
Severity breakdown
CRITICAL9HIGH522MEDIUM158LOW7
Vulnerabilities
Page 33 of 35
CVE-2026-64899P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-64899 [MEDIUM] CWE-125 CVE-2026-64899: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-68802P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-68802 [MEDIUM] CWE-125 CVE-2026-68802: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-68813P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-68813 [MEDIUM] CWE-125 CVE-2026-68813: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-63524P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-63524 [MEDIUM] CWE-125 CVE-2026-63524: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-63529P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-63529 [MEDIUM] CWE-125 CVE-2026-63529: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-68808P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-68808 [MEDIUM] CWE-125 CVE-2026-68808: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2022-22716P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2022-02-09
CVE-2022-22716 [MEDIUM] CWE-119 CVE-2022-22716: Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
nvd
CVE-2021-28456P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2021-04-13
CVE-2021-28456 [MEDIUM] CVE-2021-28456: Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
nvd
CVE-2021-31174P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2021-05-11
CVE-2021-31174 [MEDIUM] CWE-125 CVE-2021-31174: Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
nvd
CVE-2020-17020P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2020-11-11
CVE-2020-17020 [MEDIUM] CVE-2020-17020: Microsoft Word Security Feature Bypass Vulnerability
Microsoft Word Security Feature Bypass Vulnerability
nvd
CVE-2025-48812P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2025-07-08
CVE-2025-48812 [MEDIUM] CWE-125 CVE-2025-48812: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2024-38200MEDIUMCVSS 6.5PoC≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2024-08-08
CVE-2024-38200 [MEDIUM] CWE-200 Microsoft Office Spoofing Vulnerability
Microsoft Office Spoofing Vulnerability
Microsoft Office Spoofing Vulnerability
cvelistv5
CVE-2026-62882P4MEDIUMCVSS 4.3≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-62882 [MEDIUM] CWE-522 CVE-2026-62882: Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to
Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2021-42295P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2021-12-15
CVE-2021-42295 [MEDIUM] CVE-2021-42295: Visual Basic for Applications Information Disclosure Vulnerability
Visual Basic for Applications Information Disclosure Vulnerability
nvd
CVE-2019-1204P4MEDIUMCVSS 4.3≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2019-08-14
CVE-2019-1204 [MEDIUM] CWE-20 CVE-2019-1204: An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incomi
An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a local or remote message store (over SMB).
To exploit the vulnerability, the att
nvd
CVE-2024-49065P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2024-12-12
CVE-2024-49065 [MEDIUM] CWE-125 CVE-2024-49065: Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2026-55121P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-07-14
CVE-2026-55121 [MEDIUM] CWE-125 CVE-2026-55121: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2023-36767P4MEDIUMCVSS 4.3≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2023-09-12
CVE-2023-36767 [MEDIUM] CWE-20 CVE-2023-36767: Microsoft Office Security Feature Bypass Vulnerability
Microsoft Office Security Feature Bypass Vulnerability
nvd
CVE-2026-72976P4MEDIUMCVSS 5.0≥ 19.0.0, < 16.0.10417.202072026-09-08
CVE-2026-72976 [MEDIUM] CWE-125 CVE-2026-72976: Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information lo
Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally.
nvd
CVE-2026-45460P4MEDIUMCVSS 4.7≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-06-09
CVE-2026-45460 [MEDIUM] CWE-126 CVE-2026-45460: Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally
Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd