Microsoft Office vulnerabilities
1,005 known vulnerabilities affecting microsoft/office.
Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6
Vulnerabilities
Page 46 of 51
CVE-2025-59235P4HIGHCVSS 7.1v20192025-10-14
CVE-2025-59235 [HIGH] CWE-125 CVE-2025-59235: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2025-60726P4HIGHCVSS 7.1v20192025-11-11
CVE-2025-60726 [HIGH] CWE-125 CVE-2025-60726: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2025-62202P4HIGHCVSS 7.1v20192025-11-11
CVE-2025-62202 [HIGH] CWE-125 CVE-2025-62202: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2016-0141P4MEDIUMCVSS 6.5v2007v2010+2 more2016-09-14
CVE-2016-0141 [MEDIUM] CWE-200 CVE-2016-0141: The Visual Basic macros in Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 export a certific
The Visual Basic macros in Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 export a certificate-store private key during a document-save operation, which allows attackers to obtain sensitive information via unspecified vectors, aka "Microsoft Information Disclosure Vulnerability."
nvd
CVE-2020-1493P4MEDIUMCVSS 5.5v20192020-08-17
CVE-2020-1493 [MEDIUM] CWE-922 CVE-2020-1493: An information disclosure vulnerability exists when attaching files to Outlook messages. This vulner
An information disclosure vulnerability exists when attaching files to Outlook messages. This vulnerability could potentially allow users to share attached files such that they are accessible by anonymous users where they should be restricted to specific users.
To exploit this vulnerability, an attacker would have to attach a file as a link to an emai
nvd
CVE-2014-6362P4MEDIUMCVSS 4.3v2007v2010+1 more2015-02-11
CVE-2014-6362 [MEDIUM] CVE-2014-6362: Use-after-free vulnerability in Microsoft Office 2007 SP3, 2010 SP2, and 2013 Gold and SP1 allows re
Use-after-free vulnerability in Microsoft Office 2007 SP3, 2010 SP2, and 2013 Gold and SP1 allows remote attackers to bypass the ASLR protection mechanism via a crafted document, aka "Microsoft Office Component Use After Free Vulnerability."
nvd
CVE-2006-2387P4MEDIUMCVSS 5.1v2000v2001+3 more2006-10-10
CVE-2006-2387 [MEDIUM] CVE-2006-2387: Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, Excel View
Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, Excel Viewer 2003, and Microsoft Works Suite 2004 through 2006 allows user-assisted attackers to execute arbitrary code via a crafted DATETIME record in an XLS file, a different vulnerability than CVE-2006-3867 and CVE-2006-3875.
nvd
CVE-2025-59232P4HIGHCVSS 7.1v20192025-10-14
CVE-2025-59232 [HIGH] CWE-125 CVE-2025-59232: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-32188P4HIGHCVSS 7.1v20192026-04-14
CVE-2026-32188 [HIGH] CWE-125 CVE-2026-32188: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2024-49059P4HIGHCVSS 7.0v2016v20192024-12-12
CVE-2024-49059 [HIGH] CWE-59 CVE-2024-49059: Microsoft Office Elevation of Privilege Vulnerability
Microsoft Office Elevation of Privilege Vulnerability
nvd
CVE-2021-31178P4MEDIUMCVSS 5.5v2013v2016+1 more2021-05-11
CVE-2021-31178 [MEDIUM] CWE-191 CVE-2021-31178: Microsoft Office Information Disclosure Vulnerability
Microsoft Office Information Disclosure Vulnerability
nvd
CVE-2018-1007P4MEDIUMCVSS 5.3v20162018-04-12
CVE-2018-1007 [MEDIUM] CVE-2018-1007: An information disclosure vulnerability exists when Microsoft Office improperly discloses the conten
An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka "Microsoft Office Information Disclosure Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-0950.
nvd
CVE-2025-54905P4HIGHCVSS 7.1v20192025-09-09
CVE-2025-54905 [HIGH] CWE-822 CVE-2025-54905: Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose i
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
CVE-2023-36568P4HIGHCVSS 7.0v20192023-10-10
CVE-2023-36568 [HIGH] CWE-59 CVE-2023-36568: Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
nvd
CVE-2023-36565P4HIGHCVSS 7.0fixed in 16.0.14326.21606v20192023-10-10
CVE-2023-36565 [HIGH] CWE-416 CVE-2023-36565: Microsoft Office Graphics Elevation of Privilege Vulnerability
Microsoft Office Graphics Elevation of Privilege Vulnerability
nvd
CVE-2025-53736P4MEDIUMCVSS 6.2v20192025-08-12
CVE-2025-53736 [MEDIUM] CWE-126 CVE-2025-53736: Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information lo
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
CVE-2018-8378P4MEDIUMCVSS 5.5v2010-sp2v2013-sp1+1 more2018-08-15
CVE-2018-8378 [MEDIUM] CWE-125 CVE-2018-8378: An information disclosure vulnerability exists when Microsoft Office software reads out of bound mem
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka "Microsoft Office Information Disclosure Vulnerability." This affects Word, Microsoft SharePoint Server, Microsoft Office Word Viewer, Microsoft Excel Viewer, Microso
nvd
CVE-2019-1461P4MEDIUMCVSS 6.5v2010v20192019-12-10
CVE-2019-1461 [MEDIUM] CVE-2019-1461: A denial of service vulnerability exists in Microsoft Word software when the software fails to prope
A denial of service vulnerability exists in Microsoft Word software when the software fails to properly handle objects in memory, aka 'Microsoft Word Denial of Service Vulnerability'.
nvd
CVE-2018-8163P4MEDIUMCVSS 5.5v20162018-05-09
CVE-2018-8163 [MEDIUM] CWE-200 CVE-2018-8163: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the content
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Office, Microsoft Excel.
nvd
CVE-2017-11934P4MEDIUMCVSS 5.5v2013v20162017-12-12
CVE-2017-11934 [MEDIUM] CWE-200 CVE-2017-11934: Microsoft Office 2013 RT SP1, Microsoft Office 2013 SP1, and Microsoft Office 2016 allow an informat
Microsoft Office 2013 RT SP1, Microsoft Office 2013 SP1, and Microsoft Office 2016 allow an information disclosure vulnerability due to the way certain functions handle objects in memory, aka "Microsoft Office Information Disclosure Vulnerability".
nvd