Microsoft Office vulnerabilities
1,005 known vulnerabilities affecting microsoft/office.
Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6
Vulnerabilities
Page 45 of 51
CVE-2006-0029P3MEDIUMCVSS 5.1v2000v2003+3 more2006-03-14
CVE-2006-0029 [MEDIUM] CVE-2006-0029: Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and
Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.
nvd
CVE-2013-0095P4MEDIUMCVSS 5.0v2008v20112013-03-13
CVE-2013-0095 [MEDIUM] CWE-200 CVE-2013-0095: Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows
Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5 elements and leveraging the installation of a WebKit browser on the victim's machine, aka "Unintended Conte
nvd
CVE-2018-8244P3MEDIUMCVSS 6.5v20162018-06-14
CVE-2018-8244 [MEDIUM] CWE-20 CVE-2018-8244: An elevation of privilege vulnerability exists when Microsoft Outlook does not validate attachment h
An elevation of privilege vulnerability exists when Microsoft Outlook does not validate attachment headers properly, aka "Microsoft Outlook Elevation of Privilege Vulnerability." This affects Microsoft Office, Microsoft Outlook.
nvd
CVE-2021-42293P3MEDIUMCVSS 6.5v2013v2013_rt+2 more2021-12-15
CVE-2021-42293 [MEDIUM] CVE-2021-42293: Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerabilit
Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability
nvd
CVE-2002-0152P4HIGHCVSS 7.5v2001vv.x2002-04-22
CVE-2002-0152 [HIGH] CVE-2002-0152: Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a d
Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. X, 2001, and 98, and Excel v.
nvd
CVE-2026-20943P4HIGHCVSS 7.0v20162026-01-13
CVE-2026-20943 [HIGH] CWE-426 CVE-2026-20943: Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.
Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2019-0559P3MEDIUMCVSS 6.5v2019v365 ProPlus for 32-bit Systems+1 more2019-01-08
CVE-2019-0559 [MEDIUM] CVE-2019-0559: An information disclosure vulnerability exists when Microsoft Outlook improperly handles certain typ
An information disclosure vulnerability exists when Microsoft Outlook improperly handles certain types of messages, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook.
nvd
CVE-2017-8695P3MEDIUMCVSS 5.3v20112017-09-13
CVE-2017-8695 [MEDIUM] CWE-200 CVE-2017-8695: Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windo
Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, 1607, 1703, and Server 2016; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live
nvd
CVE-2002-0619P4HIGHCVSS 7.5v2000vxp2002-08-12
CVE-2002-0619 [HIGH] CVE-2002-0619: The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system
The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system, allows remote attackers to execute Visual Basic (VBA) scripts within a mail merge document that is saved in HTML format, aka a "Variant of MS00-071, Word Mail Merge Vulnerability" (CVE-2000-0788).
nvd
CVE-2017-8534P3MEDIUMCVSS 6.5v2007v20102017-06-15
CVE-2017-8534 [MEDIUM] CVE-2017-8534: Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gol
Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, Windows Server 2016, Microsoft Office 2007 SP3, and Microsoft Office 2010 SP2 allows improper disclosure of memory contents, aka "Windows Uniscribe Information Disclosure Vulnerability". This CVE ID is uniq
nvd
CVE-2018-8150P3MEDIUMCVSS 6.5v20162018-05-09
CVE-2018-8150 [MEDIUM] CVE-2018-8150: A security feature bypass vulnerability exists when the Microsoft Outlook attachment block filter do
A security feature bypass vulnerability exists when the Microsoft Outlook attachment block filter does not properly handle attachments, aka "Microsoft Outlook Security Feature Bypass Vulnerability." This affects Microsoft Office.
nvd
CVE-2018-0850P3MEDIUMCVSS 6.5v20162018-02-15
CVE-2018-0850 [MEDIUM] CVE-2018-0850: Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, Microsoft Outlook 2016, and
Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, Microsoft Outlook 2016, and Microsoft Office 2016 Click-to-Run allow an elevation of privilege vulnerability due to how the format of incoming message is validated, aka "Microsoft Outlook Elevation of Privilege Vulnerability".
nvd
CVE-2019-0540P4MEDIUMCVSS 5.5v2010v2013+2 more2019-03-05
CVE-2019-0540 [MEDIUM] CWE-601 CVE-2019-0540: A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attac
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'.
nvd
CVE-2018-8246P4MEDIUMCVSS 5.5v2010-sp2v20162018-06-14
CVE-2018-8246 [MEDIUM] CWE-200 CVE-2018-8246: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the content
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.
nvd
CVE-2024-38173P4MEDIUMCVSS 6.7v20192024-08-13
CVE-2024-38173 [MEDIUM] CWE-73 CVE-2024-38173: Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
nvd
CVE-2025-21357P4MEDIUMCVSS 6.7v20192025-01-14
CVE-2025-21357 [MEDIUM] CWE-908 CVE-2025-21357: Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
nvd
CVE-2019-0669P4MEDIUMCVSS 6.5v2010v2016+1 more2019-03-05
CVE-2019-0669 [MEDIUM] CVE-2019-0669: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the content
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.
nvd
CVE-2020-1322P4MEDIUMCVSS 6.5v20192020-06-09
CVE-2020-1322 [MEDIUM] CWE-125 CVE-2020-1322: An information disclosure vulnerability exists when Microsoft Project reads out of bound memory due
An information disclosure vulnerability exists when Microsoft Project reads out of bound memory due to an uninitialized variable, aka 'Microsoft Project Information Disclosure Vulnerability'.
nvd
CVE-2002-0618P4HIGHCVSS 7.5v2000vxp2002-08-12
CVE-2002-0618 [HIGH] CVE-2002-0618: The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to exe
The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding HTML scripts within an Excel workbook that contains an XSL stylesheet, aka "Excel XSL Stylesheet Script Execution".
nvd
CVE-2021-27055P4HIGHCVSS 7.0v20192021-03-11
CVE-2021-27055 [HIGH] CVE-2021-27055: Microsoft Visio Security Feature Bypass Vulnerability
Microsoft Visio Security Feature Bypass Vulnerability
nvd