Microsoft Office vulnerabilities
1,005 known vulnerabilities affecting microsoft/office.
Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6
Vulnerabilities
Page 34 of 51
CVE-2021-40481P3HIGHCVSS 7.8v20192021-10-13
CVE-2021-40481 [HIGH] CVE-2021-40481: Microsoft Office Visio Remote Code Execution Vulnerability
Microsoft Office Visio Remote Code Execution Vulnerability
nvd
CVE-2021-40480P3HIGHCVSS 7.8v20192021-10-13
CVE-2021-40480 [HIGH] CVE-2021-40480: Microsoft Office Visio Remote Code Execution Vulnerability
Microsoft Office Visio Remote Code Execution Vulnerability
nvd
CVE-2021-43875P3HIGHCVSS 7.8v20192021-12-15
CVE-2021-43875 [HIGH] CVE-2021-43875: Microsoft Office Graphics Remote Code Execution Vulnerability
Microsoft Office Graphics Remote Code Execution Vulnerability
nvd
CVE-2021-38658P3HIGHCVSS 7.8v2013v2016+1 more2021-09-15
CVE-2021-38658 [HIGH] CWE-843 CVE-2021-38658: Microsoft Office Graphics Remote Code Execution Vulnerability
Microsoft Office Graphics Remote Code Execution Vulnerability
nvd
CVE-2021-38654P3HIGHCVSS 7.8v20192021-09-15
CVE-2021-38654 [HIGH] CWE-129 CVE-2021-38654: Microsoft Office Visio Remote Code Execution Vulnerability
Microsoft Office Visio Remote Code Execution Vulnerability
nvd
CVE-2021-38653P3HIGHCVSS 7.8v20192021-09-15
CVE-2021-38653 [HIGH] CWE-787 CVE-2021-38653: Microsoft Office Visio Remote Code Execution Vulnerability
Microsoft Office Visio Remote Code Execution Vulnerability
nvd
CVE-2019-1199P3HIGHCVSS 7.8v20192019-08-14
CVE-2019-1199 [HIGH] CWE-787 CVE-2019-1199: A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properl
A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affec
nvd
CVE-2006-3877P3CRITICALCVSS 9.3v2000v2003+2 more2006-10-10
CVE-2006-3877 [CRITICAL] CVE-2006-3877: Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2
Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876.
nvd
CVE-2021-28453P3HIGHCVSS 7.8v20192021-04-13
CVE-2021-28453 [HIGH] CVE-2021-28453: Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2020-16957P3HIGHCVSS 7.8v20192020-10-16
CVE-2020-16957 [HIGH] CVE-2020-16957: <p>A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update address
nvd
CVE-2021-27053P3HIGHCVSS 7.8v20192021-03-11
CVE-2021-27053 [HIGH] CVE-2021-27053: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2021-41368P3HIGHCVSS 7.8v2013v2016+1 more2021-11-10
CVE-2021-41368 [HIGH] CVE-2021-41368: Microsoft Access Remote Code Execution Vulnerability
Microsoft Access Remote Code Execution Vulnerability
nvd
CVE-2020-16954P3HIGHCVSS 7.8v2010v2013+2 more2020-10-16
CVE-2020-16954 [HIGH] CVE-2020-16954: <p>A remote code execution vulnerability exists in Microsoft Office software when the software fails
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the aff
nvd
CVE-2020-17124P3HIGHCVSS 7.8v20192020-12-10
CVE-2020-17124 [HIGH] CVE-2020-17124: Microsoft PowerPoint Remote Code Execution Vulnerability
Microsoft PowerPoint Remote Code Execution Vulnerability
nvd
CVE-2020-1563P3HIGHCVSS 7.8v2010v2013+2 more2020-08-17
CVE-2020-1563 [HIGH] CVE-2020-1563: A remote code execution vulnerability exists in Microsoft Office software when the software fails to
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affec
nvd
CVE-2021-27056P3HIGHCVSS 7.8v20192021-03-11
CVE-2021-27056 [HIGH] CVE-2021-27056: Microsoft PowerPoint Remote Code Execution Vulnerability
Microsoft PowerPoint Remote Code Execution Vulnerability
nvd
CVE-2004-0848P3HIGHCVSS 7.5vxp2005-02-08
CVE-2004-0848 [HIGH] CVE-2004-0848: Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link
Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.
nvd
CVE-2016-3262P3MEDIUMCVSS 5.5v2007v20102016-10-14
CVE-2016-3262 [MEDIUM] CWE-200 CVE-2016-3262: Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeti
nvd
CVE-2016-3263P3MEDIUMCVSS 5.5v2007v20102016-10-14
CVE-2016-3263 [MEDIUM] CVE-2016-3263: Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007
nvd
CVE-2024-30042P3HIGHCVSS 7.8v20192024-05-14
CVE-2024-30042 [HIGH] CWE-502 CVE-2024-30042: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd