Microsoft Office vulnerabilities
1,005 known vulnerabilities affecting microsoft/office.
Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6
Vulnerabilities
Page 21 of 51
CVE-2026-40358P3HIGHCVSS 8.4v2016v20192026-05-12
CVE-2026-40358 [HIGH] CWE-416 CVE-2026-40358: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2016-3280P3HIGHCVSS 7.8v20102016-07-13
CVE-2016-3280 [HIGH] CWE-119 CVE-2016-3280: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for M
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2018-8575P3HIGHCVSS 7.8v365 ProPlus for 32-bit Systemsv365 ProPlus for 64-bit Systems2018-11-14
CVE-2018-8575 [HIGH] CVE-2018-8575: A remote code execution vulnerability exists in Microsoft Project software when it fails to properly
A remote code execution vulnerability exists in Microsoft Project software when it fails to properly handle objects in memory, aka "Microsoft Project Remote Code Execution Vulnerability." This affects Microsoft Project, Office 365 ProPlus, Microsoft Project Server.
nvd
CVE-2018-8331P3HIGHCVSS 7.8v20162018-09-13
CVE-2018-8331 [HIGH] CVE-2018-8331: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office.
nvd
CVE-2016-0140P3HIGHCVSS 7.8v2007v20102016-05-11
CVE-2016-0140 [HIGH] CWE-119 CVE-2016-0140: Microsoft Office 2007 SP3, Office 2010 SP2, Word Automation Services on SharePoint Server 2010 SP2,
Microsoft Office 2007 SP3, Office 2010 SP2, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2018-0797P3HIGHCVSS 7.8v2010v20162018-01-10
CVE-2018-0797 [HIGH] CWE-787 CVE-2018-0797: Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code executio
Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memory Corruption Vulnerability".
nvd
CVE-2020-1496P3HIGHCVSS 8.8v2010v2013+2 more2020-08-17
CVE-2020-1496 [HIGH] CVE-2020-1496: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affecte
nvd
CVE-2020-1494P3HIGHCVSS 8.8v2010v2013+2 more2020-08-17
CVE-2020-1494 [HIGH] CVE-2020-1494: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affecte
nvd
CVE-2020-1495P3HIGHCVSS 8.8v2010v2013+2 more2020-08-17
CVE-2020-1495 [HIGH] CVE-2020-1495: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affecte
nvd
CVE-2023-33150P3CRITICALCVSS 9.6v20192023-07-11
CVE-2023-33150 [CRITICAL] CWE-693 CVE-2023-33150: Microsoft Office Security Feature Bypass Vulnerability
Microsoft Office Security Feature Bypass Vulnerability
nvd
CVE-2018-8158P3HIGHCVSS 7.8v2010-sp2v2013-sp1+1 more2018-05-09
CVE-2018-8158 [HIGH] CVE-2018-8158: A remote code execution vulnerability exists in Microsoft Office software when the software fails to
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-8157, CVE-2018-8161.
nvd
CVE-2018-8147P3HIGHCVSS 7.8v2010-sp2v2013-sp1+1 more2018-05-09
CVE-2018-8147 [HIGH] CVE-2018-8147: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-8148, CVE-2018-8162.
nvd
CVE-2018-8157P3HIGHCVSS 7.8v2010-sp2v2013-sp1+1 more2018-05-09
CVE-2018-8157 [HIGH] CVE-2018-8157: A remote code execution vulnerability exists in Microsoft Office software when the software fails to
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-8158, CVE-2018-8161.
nvd
CVE-2018-8148P3HIGHCVSS 7.8v2010-sp2v2013-sp1+1 more2018-05-09
CVE-2018-8148 [HIGH] CVE-2018-8148: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-8147, CVE-2018-8162.
nvd
CVE-2018-8162P3HIGHCVSS 7.8v20162018-05-09
CVE-2018-8162 [HIGH] CVE-2018-8162: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-8147, CVE-2018-8148.
nvd
CVE-2020-1498P3HIGHCVSS 8.8v2016v20192020-08-17
CVE-2020-1498 [HIGH] CVE-2020-1498: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affecte
nvd
CVE-2019-1462P3HIGHCVSS 7.8v2016v20192019-12-10
CVE-2019-1462 [HIGH] CWE-908 CVE-2019-1462: A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fail
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka 'Microsoft PowerPoint Remote Code Execution Vulnerability'.
nvd
CVE-2006-3864P3CRITICALCVSS 9.3v2000v2003+3 more2006-10-10
CVE-2006-3864 [CRITICAL] CVE-2006-3864: Unspecified vulnerability in mso.dll in Microsoft Office 2000, XP, and 2003, and Microsoft PowerPoin
Unspecified vulnerability in mso.dll in Microsoft Office 2000, XP, and 2003, and Microsoft PowerPoint 2000, XP, and 2003, allows remote user-assisted attackers to execute arbitrary code via a malformed record in a (1) .DOC, (2) .PPT, or (3) .XLS file that triggers memory corruption, related to an "array boundary condition" (possibly an array index overflow)
nvd
CVE-2012-2524P3CRITICALCVSS 9.3v2007v20102012-08-15
CVE-2012-2524 [CRITICAL] CWE-119 CVE-2012-2524: Microsoft Office 2007 SP2 and SP3 and 2010 SP1 allows remote attackers to execute arbitrary code or
Microsoft Office 2007 SP2 and SP3 and 2010 SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Computer Graphics Metafile (CGM) file, aka "CGM File Format Memory Corruption Vulnerability."
nvd
CVE-2020-0850P3HIGHCVSS 8.8v2016v20192020-03-12
CVE-2020-0850 [HIGH] CVE-2020-0850: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0851, CVE-2020-0852, CVE-2020-0855, CVE-2020-0892.
nvd