Microsoft Office vulnerabilities
1,005 known vulnerabilities affecting microsoft/office.
Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6
Vulnerabilities
Page 32 of 51
CVE-2021-40486P3HIGHCVSS 7.8v20192021-10-13
CVE-2021-40486 [HIGH] CVE-2021-40486: Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2021-38655P3HIGHCVSS 7.8v20192021-09-15
CVE-2021-38655 [HIGH] CWE-416 CVE-2021-38655: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2020-16932P3HIGHCVSS 7.8v20192020-10-16
CVE-2020-16932 [HIGH] CWE-908 CVE-2020-16932: <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of t
nvd
CVE-2020-16931P3HIGHCVSS 7.8v20192020-10-16
CVE-2020-16931 [HIGH] CWE-908 CVE-2020-16931: <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of t
nvd
CVE-2020-16930P3HIGHCVSS 7.8v2013v2016+1 more2020-10-16
CVE-2020-16930 [HIGH] CWE-787 CVE-2020-16930: <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of t
nvd
CVE-2020-16929P3HIGHCVSS 7.8v2010v2013+2 more2020-10-16
CVE-2020-16929 [HIGH] CWE-416 CVE-2020-16929: <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of t
nvd
CVE-2004-0846P3HIGHCVSS 7.5v2000v2001+1 more2004-11-03
CVE-2004-0846 [HIGH] CVE-2004-0846: Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote att
Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.
nvd
CVE-2024-20677P3HIGHCVSS 7.8v20192024-01-09
CVE-2024-20677 [HIGH] CWE-122 CVE-2024-20677: A security vulnerability exists in FBX that could lead to remote code execution. To mitigate this vu
A security vulnerability exists in FBX that could lead to remote code execution. To mitigate this vulnerability, the ability to insert FBX files has been disabled in Word, Excel, PowerPoint and Outlook for Windows and Mac. Versions of Office that had this feature enabled will no longer have access to it. This includes Office 2019, Office 2021, Office
nvd
CVE-2006-3876P3CRITICALCVSS 9.3v2000v2001+2 more2006-10-10
CVE-2006-3876 [CRITICAL] CWE-94 CVE-2006-3876: Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2
Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via a crafted Data record in a PPT file, a different vulnerability than CVE-2006-3435 and CVE-2006-4694.
nvd
CVE-2010-3337P3CRITICALCVSS 9.3v2007v20102010-11-10
CVE-2010-3337 [CRITICAL] CVE-2010-3337: Untrusted search path vulnerability in Microsoft Office 2007 SP2 and 2010 allows local users to gain
Untrusted search path vulnerability in Microsoft Office 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Insecure Library Loading Vulnerability." NOTE: this might overlap CVE-2010-3141 and CVE-2010-3142.
nvd
CVE-2020-17128P3HIGHCVSS 7.8v2010v2016+1 more2020-12-10
CVE-2020-17128 [HIGH] CVE-2020-17128: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2011-1980P3CRITICALCVSS 9.3v2003v20072011-09-15
CVE-2011-1980 [CRITICAL] CVE-2011-1980: Untrusted search path vulnerability in Microsoft Office 2003 SP3 and 2007 SP2 allows local users to
Untrusted search path vulnerability in Microsoft Office 2003 SP3 and 2007 SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .doc, .ppt, or .xls file, aka "Office Component Insecure Library Loading Vulnerability."
nvd
CVE-2016-7233P3MEDIUMCVSS 6.5v20102016-11-10
CVE-2016-7233 [MEDIUM] CWE-200 CVE-2016-7233: Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Vie
Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a c
nvd
CVE-2025-26630P3HIGHCVSS 7.8v20192025-03-11
CVE-2025-26630 [HIGH] CWE-416 CVE-2025-26630: Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-27750P3HIGHCVSS 7.8v20192025-04-08
CVE-2025-27750 [HIGH] CWE-416 CVE-2025-27750: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-27747P3HIGHCVSS 7.8v20192025-04-08
CVE-2025-27747 [HIGH] CWE-822 CVE-2025-27747: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-29820P3HIGHCVSS 7.8v2016v20192025-04-08
CVE-2025-29820 [HIGH] CWE-416 CVE-2025-29820: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-20946P3HIGHCVSS 7.8v20192026-01-13
CVE-2026-20946 [HIGH] CWE-125 CVE-2026-20946: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-24082P3HIGHCVSS 7.8v20192025-03-11
CVE-2025-24082 [HIGH] CWE-416 CVE-2025-24082: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-24080P3HIGHCVSS 7.8v2016v20192025-03-11
CVE-2025-24080 [HIGH] CWE-416 CVE-2025-24080: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd