cbcvebase.

Microsoft Office vulnerabilities

1,005 known vulnerabilities affecting microsoft/office.

Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6

Vulnerabilities

Page 49 of 51
CVE-2025-48812P4MEDIUMCVSS 5.5v20192025-07-08
CVE-2025-48812 [MEDIUM] CWE-125 CVE-2025-48812: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2002-0617P4MEDIUMCVSS 5.1v2000vxp2002-08-12
CVE-2002-0617 [MEDIUM] CVE-2002-0617: The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to exe The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by creating a hyperlink on a drawing shape in a source workbook that points to a destination workbook containing an autoexecute macro, aka "Hyperlinked Excel Workbook Macro Bypass."
nvd
CVE-2019-1402P4MEDIUMCVSS 5.5v2010v2013+2 more2019-11-12
CVE-2019-1402 [MEDIUM] CWE-200 CVE-2019-1402: An information disclosure vulnerability exists in Microsoft Office software when the software fails An information disclosure vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Information Disclosure Vulnerability'.
nvd
CVE-2018-8427P4MEDIUMCVSS 5.5v2016v2019+2 more2018-10-10
CVE-2018-8427 [MEDIUM] CWE-200 CVE-2018-8427: An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Information Disclosure Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Windows Server 2008, Microsoft PowerPoint Viewer, Microsoft Excel Viewer.
nvd
CVE-2019-1463P4MEDIUMCVSS 5.5v2010v2013+2 more2019-12-10
CVE-2019-1463 [MEDIUM] CVE-2019-1463: An information disclosure vulnerability exists in Microsoft Access software when the software fails An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory, aka 'Microsoft Access Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1400.
nvd
CVE-2019-1400P4MEDIUMCVSS 5.5v2010v2013+2 more2019-12-10
CVE-2019-1400 [MEDIUM] CWE-200 CVE-2019-1400: An information disclosure vulnerability exists in Microsoft Access software when the software fails An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory, aka 'Microsoft Access Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1463.
nvd
CVE-2019-1204P4MEDIUMCVSS 4.3v20192019-08-14
CVE-2019-1204 [MEDIUM] CWE-20 CVE-2019-1204: An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incomi An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a local or remote message store (over SMB). To exploit the vulnerability, the att
nvd
CVE-2024-49065P4MEDIUMCVSS 5.5v20192024-12-12
CVE-2024-49065 [MEDIUM] CWE-125 CVE-2024-49065: Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2020-1229P4MEDIUMCVSS 4.3v2010v2013+2 more2020-06-09
CVE-2020-1229 [MEDIUM] CVE-2020-1229: A security feature bypass vulnerability exists in Microsoft Outlook when Office fails to enforce sec A security feature bypass vulnerability exists in Microsoft Outlook when Office fails to enforce security settings configured on a system, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'.
nvd
CVE-2023-36767P4MEDIUMCVSS 4.3v2013v2016+1 more2023-09-12
CVE-2023-36767 [MEDIUM] CWE-20 CVE-2023-36767: Microsoft Office Security Feature Bypass Vulnerability Microsoft Office Security Feature Bypass Vulnerability
nvd
CVE-2012-1894P4MEDIUMCVSS 6.9v20112012-07-10
CVE-2012-1894 [MEDIUM] CWE-264 CVE-2012-1894: Microsoft Office for Mac 2011 uses world-writable permissions for the "Applications/Microsoft Office Microsoft Office for Mac 2011 uses world-writable permissions for the "Applications/Microsoft Office 2011/" directory and certain other directories, which allows local users to gain privileges by placing a Trojan horse executable file in one of these directories, aka "Office for Mac Improper Folder Permissions Vulnerability."
nvd
CVE-2008-3003P4MEDIUMCVSS 6.6v20072008-08-12
CVE-2008-3003 [MEDIUM] CWE-20 CVE-2008-3003: Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from con Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data session password, which allows local users to obtain sensitive information and obtain access to a remote data source, aka the "Excel Credential Caching Vulnerability."
nvd
CVE-2026-40421P4MEDIUMCVSS 4.3v2019v20242026-05-12
CVE-2026-40421 [MEDIUM] CWE-73 CVE-2026-40421: Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
CVE-2021-42295P4MEDIUMCVSS 5.5v2013v2016+1 more2021-12-15
CVE-2021-42295 [MEDIUM] CVE-2021-42295: Visual Basic for Applications Information Disclosure Vulnerability Visual Basic for Applications Information Disclosure Vulnerability
nvd
CVE-2021-43255P4MEDIUMCVSS 5.5v2013v2013_rt+2 more2021-12-15
CVE-2021-43255 [MEDIUM] CVE-2021-43255: Microsoft Office Trust Center Spoofing Vulnerability Microsoft Office Trust Center Spoofing Vulnerability
nvd
CVE-2014-1808P4MEDIUMCVSS 4.3v20132014-05-14
CVE-2014-1808 [MEDIUM] CWE-200 CVE-2014-1808: Microsoft Office 2013 Gold, SP1, RT, and RT SP1 allows remote attackers to obtain sensitive token in Microsoft Office 2013 Gold, SP1, RT, and RT SP1 allows remote attackers to obtain sensitive token information via a web site that sends a crafted response during opening of an Office document, aka "Token Reuse Vulnerability."
nvd
CVE-2022-41104P4MEDIUMCVSS 5.5v20192022-11-09
CVE-2022-41104 [MEDIUM] CVE-2022-41104: Microsoft Excel Security Feature Bypass Vulnerability Microsoft Excel Security Feature Bypass Vulnerability
nvd
CVE-2015-1639P4MEDIUMCVSS 4.3v20112015-04-14
CVE-2015-1639 [MEDIUM] CWE-79 CVE-2015-1639: Cross-site scripting (XSS) vulnerability in Microsoft Office for Mac 2011 allows remote attackers to Cross-site scripting (XSS) vulnerability in Microsoft Office for Mac 2011 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Microsoft Outlook App for Mac XSS Vulnerability."
nvd
CVE-2001-0003P4MEDIUMCVSS 5.0v20002001-02-12
CVE-2001-0003 [MEDIUM] CVE-2001-0003: Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly p Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.
nvd
CVE-2013-3859P4MEDIUMCVSS 6.9v20102013-09-11
CVE-2013-3859 [MEDIUM] CWE-264 CVE-2013-3859: Microsoft Pinyin IME 2010, when used in conjunction with Microsoft Office 2010 SP1, does not properl Microsoft Pinyin IME 2010, when used in conjunction with Microsoft Office 2010 SP1, does not properly restrict configuration options, which allows local users to gain privileges by starting Internet Explorer from the IME toolbar, aka "Chinese IME Vulnerability."
nvd
Microsoft Office vulnerabilities | cvebase