Microsoft Office vulnerabilities
1,005 known vulnerabilities affecting microsoft/office.
Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6
Vulnerabilities
Page 27 of 51
CVE-2017-0282P4MEDIUMCVSS 5.0PoCv2007v20102017-06-15
CVE-2017-0282 [MEDIUM] CWE-200 CVE-2017-0282: Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gol
Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016, Microsoft Office 2007 SP3, and Microsoft Office 2010 SP2 allows improper disclosure of memory contents, aka "Windows Uniscribe Information Disclosure Vulnerability". This
nvd
CVE-2025-62553P3HIGHCVSS 7.8v20192025-12-09
CVE-2025-62553 [HIGH] CWE-416 CVE-2025-62553: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-62562P3HIGHCVSS 7.8v20192025-12-09
CVE-2025-62562 [HIGH] CWE-416 CVE-2025-62562: Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-62563P3HIGHCVSS 7.8v20192025-12-09
CVE-2025-62563 [HIGH] CWE-416 CVE-2025-62563: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-59234P3HIGHCVSS 7.8v2016v20192025-10-14
CVE-2025-59234 [HIGH] CWE-416 CVE-2025-59234: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-21259P3HIGHCVSS 7.8v20192026-02-10
CVE-2026-21259 [HIGH] CWE-122 CVE-2026-21259: Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate priv
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-42831P3HIGHCVSS 7.8v20242026-05-12
CVE-2026-42831 [HIGH] CWE-122 CVE-2026-42831: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2024-43504P3HIGHCVSS 7.8v20192024-10-08
CVE-2024-43504 [HIGH] CWE-416 CVE-2024-43504: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2020-0980P3HIGHCVSS 7.8v2010v2016+1 more2020-04-15
CVE-2020-0980 [HIGH] CVE-2020-0980: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'.
nvd
CVE-2020-0961P3HIGHCVSS 7.8v2010v2013+2 more2020-04-15
CVE-2020-0961 [HIGH] CVE-2020-0961: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine im
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'.
nvd
CVE-2019-0673P3HIGHCVSS 7.8v2010v2013+2 more2019-03-05
CVE-2019-0673 [HIGH] CVE-2019-0673: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine im
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0671, CVE-2019-0672, CVE-2019-0674, CVE-2019-0675.
nvd
CVE-2019-0671P3HIGHCVSS 7.8v2010v2013+2 more2019-03-05
CVE-2019-0671 [HIGH] CVE-2019-0671: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine im
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0672, CVE-2019-0673, CVE-2019-0674, CVE-2019-0675.
nvd
CVE-2019-0672P3HIGHCVSS 7.8v2010v2013+2 more2019-03-05
CVE-2019-0672 [HIGH] CVE-2019-0672: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine im
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0671, CVE-2019-0673, CVE-2019-0674, CVE-2019-0675.
nvd
CVE-2019-0675P3HIGHCVSS 7.8v20102019-03-05
CVE-2019-0675 [HIGH] CVE-2019-0675: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine im
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0671, CVE-2019-0672, CVE-2019-0673, CVE-2019-0674.
nvd
CVE-2025-21362P3HIGHCVSS 8.4v20192025-01-14
CVE-2025-21362 [HIGH] CWE-416 CVE-2025-21362: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2025-47167P3HIGHCVSS 8.4v2016v20192025-06-10
CVE-2025-47167 [HIGH] CWE-843 CVE-2025-47167: Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthor
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-53733P3HIGHCVSS 8.4v20192025-08-12
CVE-2025-53733 [HIGH] CWE-681 CVE-2025-53733: Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker
Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2019-0748P3HIGHCVSS 7.8v20102019-04-09
CVE-2019-0748 [HIGH] CVE-2019-0748: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine im
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'.
nvd
CVE-2024-30101P3HIGHCVSS 7.5v2016v20192024-06-11
CVE-2024-30101 [HIGH] CWE-416 CVE-2024-30101: Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2006-0033P3CRITICALCVSS 9.3v2000v2003+1 more2006-07-11
CVE-2006-0033 [CRITICAL] CVE-2006-0033: Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and
Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted PNG image that triggers memory corruption when it is parsed.
nvd