cbcvebase.

Microsoft Office vulnerabilities

1,005 known vulnerabilities affecting microsoft/office.

Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6

Vulnerabilities

Page 7 of 51
CVE-2016-3209P3MEDIUMCVSS 5.5PoCv2007v20102016-10-14
CVE-2016-3209 [MEDIUM] CWE-200 CVE-2016-3209: Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; Live Meeting 2
nvd
CVE-2021-34501P2HIGHCVSS 8.8v20192021-07-14
CVE-2021-34501 [HIGH] CVE-2021-34501: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2017-8550P3MEDIUMCVSS 5.4PoCv20162017-06-15
CVE-2017-8550 [MEDIUM] CWE-79 CVE-2017-8550: A remote code execution vulnerability exists in Skype for Business when the software fails to saniti A remote code execution vulnerability exists in Skype for Business when the software fails to sanitize specially crafted content, aka "Skype for Business Remote Code Execution Vulnerability".
nvd
CVE-2025-47175P3HIGHCVSS 7.8PoCv20192025-06-10
CVE-2025-47175 [HIGH] CWE-416 CVE-2025-47175: Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locall Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-27751P3HIGHCVSS 7.8PoCv20192025-04-08
CVE-2025-27751 [HIGH] CWE-416 CVE-2025-27751: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2004-0121P3HIGHCVSS 7.5PoCvxp2004-04-15
CVE-2004-0121 [HIGH] CWE-88 CVE-2004-0121: Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters o Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.
nvd
CVE-2015-6172P2CRITICALCVSS 9.3v20102015-12-09
CVE-2015-6172 [CRITICAL] CWE-20 CVE-2015-6172: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2016, Word 2013 RT SP1, Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2016, Word 2013 RT SP1, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted email message processed by Outlook, aka "Microsoft Office RCE Vulnerability."
nvd
CVE-2008-3471P2CRITICALCVSS 9.3v2004v20082008-10-15
CVE-2008-3471 [CRITICAL] CWE-787 CVE-2008-3471: Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold a Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 SP3; Office Excel Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allows remote attackers to ex
nvd
CVE-2000-0854P3CRITICALCVSS 10.0PoCv20002000-11-14
CVE-2000-0854 [CRITICAL] CVE-2000-0854: When a Microsoft Office 2000 document is launched, the directory of that document is first used to l When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document.
nvd
CVE-2006-0030P3MEDIUMCVSS 5.1PoCv2000v2003+3 more2006-03-14
CVE-2006-0030 [MEDIUM] CVE-2006-0030: Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.
nvd
CVE-2023-33137P3HIGHCVSS 7.8PoCv2013v2016+1 more2023-06-14
CVE-2023-33137 [HIGH] CWE-415 CVE-2023-33137: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2023-23399P3HIGHCVSS 7.8PoCv2013v2016+1 more2023-03-14
CVE-2023-23399 [HIGH] CWE-125 CVE-2023-23399: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2025-53766P2CRITICALCVSS 9.8fixed in 16.0.14326.226182025-08-12
CVE-2025-53766 [CRITICAL] CWE-122 CVE-2025-53766: Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a ne Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
nvd
CVE-2020-16947P2HIGHCVSS 8.8v20192020-10-16
CVE-2020-16947 [HIGH] CWE-125 CVE-2020-16947: <p>A remote code execution vulnerability exists in Microsoft Outlook software when the software fail A remote code execution vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the targeted user. If the targeted user is logged on with administrative user rights, an attacker could take control
nvd
CVE-2023-28285P3HIGHCVSS 7.8PoCv20192023-04-11
CVE-2023-28285 [HIGH] CWE-416 CVE-2023-28285: Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2023-28311P3HIGHCVSS 7.8PoCv20192023-04-11
CVE-2023-28311 [HIGH] CWE-122 CVE-2023-28311: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2023-33148P3HIGHCVSS 7.8PoCv2013v20192023-07-11
CVE-2023-33148 [HIGH] CWE-59 CVE-2023-33148: Microsoft Office Elevation of Privilege Vulnerability Microsoft Office Elevation of Privilege Vulnerability
nvd
CVE-2015-6108P2CRITICALCVSS 9.3v2007v20102015-12-09
CVE-2015-6108 [CRITICAL] CWE-119 CVE-2015-6108: The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT Gold and 8.1; Office 2007 SP3; Office 2010 SP2; Word Viewer; .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6; Skype for Business 2016; Lync 2010; Lync 2013 S
nvd
CVE-2008-3014P2CRITICALCVSS 9.3v2003v2007+1 more2008-09-11
CVE-2008-3014 [CRITICAL] CWE-119 CVE-2008-3014: Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services
nvd
CVE-2018-1026P2HIGHCVSS 8.8v2013v20162018-04-12
CVE-2018-1026 [HIGH] CVE-2018-1026: A remote code execution vulnerability exists in Microsoft Office software when the software fails to A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-1030.
nvd
Microsoft Office vulnerabilities | cvebase