Microsoft Office vulnerabilities
1,005 known vulnerabilities affecting microsoft/office.
Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6
Vulnerabilities
Page 22 of 51
CVE-2011-0103P3CRITICALCVSS 9.3v2004v20082011-04-13
CVE-2011-0103 [CRITICAL] CWE-119 CVE-2011-0103: Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Conver
Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted record information in an Excel file, aka "Excel Memory Corruption Vulnerability."
nvd
CVE-2017-11825P3HIGHCVSS 7.8v20162017-10-13
CVE-2017-11825 [HIGH] CWE-119 CVE-2017-11825: Microsoft Office 2016 Click-to-Run (C2R) and Microsoft Office 2016 for Mac allow an attacker to use
Microsoft Office 2016 Click-to-Run (C2R) and Microsoft Office 2016 for Mac allow an attacker to use a specially crafted file to perform actions in the security context of the current user, due to how Microsoft Office handles files in memory, aka "Microsoft Office Remote Code Execution Vulnerability".
nvd
CVE-2011-1273P3CRITICALCVSS 9.3v2004v2008+1 more2011-06-16
CVE-2011-1273 [CRITICAL] CWE-119 CVE-2011-1273: Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XM
Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to e
nvd
CVE-2011-1279P3CRITICALCVSS 9.3v2004v20082011-06-16
CVE-2011-1279 [CRITICAL] CWE-119 CVE-2011-1279: Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Conver
Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Out of Bounds
nvd
CVE-2018-0793P3HIGHCVSS 7.8v2010v20162018-01-10
CVE-2018-0793 [HIGH] CVE-2018-0793: Microsoft Outlook 2007, Microsoft Outlook 2010 and Microsoft Outlook 2013 allow a remote code execut
Microsoft Outlook 2007, Microsoft Outlook 2010 and Microsoft Outlook 2013 allow a remote code execution vulnerability due to the way email messages are parsed, aka "Microsoft Outlook Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0791.
nvd
CVE-2018-0791P3HIGHCVSS 7.8v20162018-01-10
CVE-2018-0791 [HIGH] CVE-2018-0791: Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, and Microsoft Outlook 2016 a
Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, and Microsoft Outlook 2016 allow a remote code execution vulnerability due to the way email messages are parsed, aka "Microsoft Outlook Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0793.
nvd
CVE-2018-8161P3HIGHCVSS 7.8v2010-sp2v2013-sp1+1 more2018-05-09
CVE-2018-8161 [HIGH] CVE-2018-8161: A remote code execution vulnerability exists in Microsoft Office software when the software fails to
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Word, Word, Microsoft Office, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8157, CVE-2018-8158.
nvd
CVE-2025-54910P3HIGHCVSS 8.4v2016v20192025-09-09
CVE-2025-54910 [HIGH] CWE-122 CVE-2025-54910: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-20952P3HIGHCVSS 8.4v2016v20192026-01-13
CVE-2026-20952 [HIGH] CWE-416 CVE-2026-20952: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-32190P3HIGHCVSS 8.4v2016v20192026-04-14
CVE-2026-32190 [HIGH] CWE-416 CVE-2026-32190: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2006-0001P3CRITICALCVSS 9.3v2000v2003+1 more2006-09-12
CVE-2006-0001 [CRITICAL] CWE-119 CVE-2006-0001: Stack-based buffer overflow in Microsoft Publisher 2000 through 2003 allows user-assisted remote att
Stack-based buffer overflow in Microsoft Publisher 2000 through 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted PUB file, which causes an overflow when parsing fonts.
nvd
CVE-2018-0845P3HIGHCVSS 7.8v2007v2010+2 more2018-01-22
CVE-2018-0845 [HIGH] CVE-2018-0845: Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Of
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0805, CVE-2018-0806, and CVE-2018-0807.
nvd
CVE-2016-7235P3HIGHCVSS 7.8v20102016-11-10
CVE-2016-7235 [HIGH] CWE-119 CVE-2016-7235: Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, and Offi
Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2016-7245P3HIGHCVSS 7.8v2007v2010+2 more2016-11-10
CVE-2016-7245 [HIGH] CWE-119 CVE-2016-7245: Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, and Office 2016 all
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, and Office 2016 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2016-0126P3HIGHCVSS 7.8v2013v20162016-05-11
CVE-2016-0126 [HIGH] CWE-119 CVE-2016-0126: Microsoft Office 2013 SP1, 2013 RT SP1, and 2016 allows remote attackers to execute arbitrary code v
Microsoft Office 2013 SP1, 2013 RT SP1, and 2016 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2018-8281P3HIGHCVSS 7.8v20162018-07-11
CVE-2018-8281 [HIGH] CVE-2018-8281: A remote code execution vulnerability exists in Microsoft Office software when the software fails to
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Excel Viewer, Microsoft PowerPoint Viewer, Microsoft Office, Microsoft Office Word Viewer.
nvd
CVE-2018-8312P3HIGHCVSS 7.8v20162018-07-11
CVE-2018-8312 [HIGH] CVE-2018-8312: A remote code execution vulnerability exists when Microsoft Access fails to properly handle objects
A remote code execution vulnerability exists when Microsoft Access fails to properly handle objects in memory, aka "Microsoft Access Remote Code Execution Vulnerability." This affects Microsoft Access, Microsoft Office.
nvd
CVE-2019-1109P3CRITICALCVSS 9.1v2013v2016+1 more2019-07-15
CVE-2019-1109 [CRITICAL] CWE-20 CVE-2019-1109: A spoofing vulnerability exists when Microsoft Office Javascript does not check the validity of the
A spoofing vulnerability exists when Microsoft Office Javascript does not check the validity of the web page making a request to Office documents.An attacker who successfully exploited this vulnerability could read or write information in Office documents.The security update addresses the vulnerability by correcting the way that Microsoft Office Javas
nvd
CVE-2017-11935P3HIGHCVSS 7.8v20162017-12-12
CVE-2017-11935 [HIGH] CWE-119 CVE-2017-11935: Microsoft Office 2016 Click-to-Run (C2R) allows a remote code execution vulnerability due to the way
Microsoft Office 2016 Click-to-Run (C2R) allows a remote code execution vulnerability due to the way files are handled in memory, aka "Microsoft Excel Remote Code Execution Vulnerability".
nvd
CVE-2007-0028P3CRITICALCVSS 9.3v2000vxp+3 more2007-01-09
CVE-2007-0028 [CRITICAL] CVE-2007-0028: Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not
Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an "Improper Memory Access Vulnerability." NOTE: an early disclosure of this issue used CVE-2006-3432, but only CVE-
nvd