Microsoft Office vulnerabilities
1,005 known vulnerabilities affecting microsoft/office.
Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6
Vulnerabilities
Page 29 of 51
CVE-2026-32199P3HIGHCVSS 7.8v20192026-04-14
CVE-2026-32199 [HIGH] CWE-416 CVE-2026-32199: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-32197P3HIGHCVSS 7.8v20192026-04-14
CVE-2026-32197 [HIGH] CWE-416 CVE-2026-32197: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2020-0852P3HIGHCVSS 7.8v2016v20192020-03-12
CVE-2020-0852 [HIGH] CVE-2020-0852: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0855, CVE-2020-0892.
nvd
CVE-2020-0855P3HIGHCVSS 7.8v20192020-03-12
CVE-2020-0855 [HIGH] CVE-2020-0855: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0852, CVE-2020-0892.
nvd
CVE-2020-0892P3HIGHCVSS 7.8v2010v2016+1 more2020-03-12
CVE-2020-0892 [HIGH] CVE-2020-0892: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0852, CVE-2020-0855.
nvd
CVE-2020-0851P3HIGHCVSS 7.8v2016v20192020-03-12
CVE-2020-0851 [HIGH] CVE-2020-0851: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0852, CVE-2020-0855, CVE-2020-0892.
nvd
CVE-2020-0991P3HIGHCVSS 7.8v2010v2013+2 more2020-04-15
CVE-2020-0991 [HIGH] CVE-2020-0991: A remote code execution vulnerability exists in Microsoft Office software when the software fails to
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0760.
nvd
CVE-2011-1275P3CRITICALCVSS 9.3v2004v2008+1 more2011-06-16
CVE-2011-1275 [CRITICAL] CWE-119 CVE-2011-1275: Microsoft Excel 2002 SP3; Office 2004, 2008, and 2011 for Mac; and Open XML File Format Converter fo
Microsoft Excel 2002 SP3; Office 2004, 2008, and 2011 for Mac; and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Memory Heap Overwrit
nvd
CVE-2025-47994P3HIGHCVSS 8.6v2016v20192025-07-08
CVE-2025-47994 [HIGH] CWE-502 CVE-2025-47994: Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate pri
Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2021-34469P3HIGHCVSS 8.1v2013v2016+1 more2021-07-14
CVE-2021-34469 [HIGH] CVE-2021-34469: Microsoft Office Security Feature Bypass Vulnerability
Microsoft Office Security Feature Bypass Vulnerability
nvd
CVE-2011-0107P3CRITICALCVSS 9.3v2003v2007+1 more2011-04-13
CVE-2011-0107 [CRITICAL] CVE-2011-0107: Untrusted search path vulnerability in Microsoft Office XP SP3, Office 2003 SP3, and Office 2007 SP2
Untrusted search path vulnerability in Microsoft Office XP SP3, Office 2003 SP3, and Office 2007 SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka "Office Component Insecure Library Loading Vulnerability."
nvd
CVE-2012-5672P4MEDIUMCVSS 4.3PoCv20072012-10-25
CVE-2012-5672 [MEDIUM] CVE-2012-5672: Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow rem
Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow remote attackers to cause a denial of service (read access violation and application crash) via a crafted spreadsheet file, as demonstrated by a .xls file with battery voltage data.
nvd
CVE-2019-0822P3HIGHCVSS 7.8v2016v20192019-04-09
CVE-2019-0822 [HIGH] CVE-2019-0822: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
nvd
CVE-2019-0946P3HIGHCVSS 7.8v2010v2013+2 more2019-05-16
CVE-2019-0946 [HIGH] CVE-2019-0946: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine im
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0945, CVE-2019-0947.
nvd
CVE-2019-0947P3HIGHCVSS 7.8v20102019-05-16
CVE-2019-0947 [HIGH] CVE-2019-0947: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine im
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0945, CVE-2019-0946.
nvd
CVE-2019-0945P3HIGHCVSS 7.8v2010v2013+2 more2019-05-16
CVE-2019-0945 [HIGH] CWE-19 CVE-2019-0945: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine im
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0946, CVE-2019-0947.
nvd
CVE-2006-1316P3CRITICALCVSS 9.3v2000v2003+1 more2006-07-11
CVE-2006-1316 [CRITICAL] CWE-94 CVE-2006-1316: Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and
Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with malformed string that triggers memory corruption related to record lengths, aka "Microsoft Office Parsing Vulnerability," a different vulnerability than CVE
nvd
CVE-2025-24057P3HIGHCVSS 7.8v2016v20192025-03-11
CVE-2025-24057 [HIGH] CWE-122 CVE-2025-24057: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2019-1246P3HIGHCVSS 7.8v2010v2013+2 more2019-09-11
CVE-2019-1246 [HIGH] CVE-2019-1246: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1240, CVE-2019-1241, CVE-2019-1242, CVE-2019-1243, CVE-2019-1247, CVE-2019-1248, CVE-2019-1249, CVE-2019-1250.
nvd
CVE-2025-54908P3HIGHCVSS 7.8v20192025-09-09
CVE-2025-54908 [HIGH] CWE-416 CVE-2025-54908: Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locall
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
nvd