cbcvebase.

Microsoft Office Ltsc For Mac 2024 vulnerabilities

268 known vulnerabilities affecting microsoft/microsoft_office_ltsc_for_mac_2024.

Total CVEs
268
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
3
Severity breakdown
CRITICAL1HIGH228MEDIUM31LOW8

Vulnerabilities

Page 1 of 14
CVE-2026-21514P1HIGHCVSS 7.8KEV≥ 16.0.0, < 16.106.260208212026-02-10
CVE-2026-21514 [HIGH] CWE-807 CVE-2026-21514: Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
nvd
CVE-2025-47165P1HIGHCVSS 7.8ExploitedPoC≥ 16.0.0, < 16.98.250608242025-06-10
CVE-2025-47165 [HIGH] CWE-416 CVE-2025-47165: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-47170P1HIGHCVSS 7.8Exploited≥ 16.0.0, < 16.98.250608242025-06-10
CVE-2025-47170 [HIGH] CWE-416 CVE-2025-47170: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-47175P3HIGHCVSS 7.8PoC≥ 16.0.0, < 16.98.250608242025-06-10
CVE-2025-47175 [HIGH] CWE-416 CVE-2025-47175: Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locall Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-27751P3HIGHCVSS 7.8PoC≥ 16.0.0, < 16.96.250413262025-04-08
CVE-2025-27751 [HIGH] CWE-416 CVE-2025-27751: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-60724P2CRITICALCVSS 9.8≥ 16.0.0, < 16.103.251109222025-11-11
CVE-2025-60724 [CRITICAL] CWE-122 CVE-2025-60724: Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execut Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-40364P3HIGHCVSS 8.4≥ 16.0.0, < 16.109.260510192026-05-12
CVE-2026-40364 [HIGH] CWE-122 CVE-2026-40364: Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an una Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50387P3HIGHCVSS 7.8≥ 16.0.0, < 16.111.260712152026-07-14
CVE-2026-50387 [HIGH] CWE-121 CVE-2026-50387: Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges local Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40361P3HIGHCVSS 8.4≥ 16.0.0, < 16.109.260510192026-05-12
CVE-2026-40361 [HIGH] CWE-416 CVE-2026-40361: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-20953P3HIGHCVSS 8.4≥ 16.0.0, < 16.105.260110182026-01-13
CVE-2026-20953 [HIGH] CWE-416 CVE-2026-20953: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-40363P3HIGHCVSS 8.4≥ 16.0.0, < 16.109.260510192026-05-12
CVE-2026-40363 [HIGH] CWE-122 CVE-2026-40363: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-40358P3HIGHCVSS 8.4≥ 16.0.0, < 16.109.260510192026-05-12
CVE-2026-40358 [HIGH] CWE-416 CVE-2026-40358: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-54910P3HIGHCVSS 8.4≥ 16.0.0, < 16.101.250913142025-09-09
CVE-2025-54910 [HIGH] CWE-122 CVE-2025-54910: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-20952P3HIGHCVSS 8.4≥ 16.0.0, < 16.105.260110182026-01-13
CVE-2026-20952 [HIGH] CWE-416 CVE-2026-20952: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-45461P3HIGHCVSS 8.4≥ 16.0.0, < 16.110.260613172026-06-09
CVE-2026-45461 [HIGH] CWE-416 CVE-2026-45461: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-45472P3HIGHCVSS 8.4≥ 16.0.0, < 16.110.260613172026-06-09
CVE-2026-45472 [HIGH] CWE-416 CVE-2026-45472: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-45474P3HIGHCVSS 8.4≥ 16.0.0, < 16.110.260613172026-06-09
CVE-2026-45474 [HIGH] CWE-416 CVE-2026-45474: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-45458P3HIGHCVSS 8.4≥ 16.0.0, < 16.110.260613172026-06-09
CVE-2026-45458 [HIGH] CWE-416 CVE-2026-45458: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-32190P3HIGHCVSS 8.4≥ 16.0.0, < 16.108.260412192026-04-14
CVE-2026-32190 [HIGH] CWE-416 CVE-2026-32190: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-33115P3HIGHCVSS 8.4≥ 16.0.0, < 16.108.260412192026-04-14
CVE-2026-33115 [HIGH] CWE-416 CVE-2026-33115: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
1 / 14Next →