Microsoft Office Online Server vulnerabilities
153 known vulnerabilities affecting microsoft/office_online_server.
Total CVEs
153
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
3
Severity breakdown
CRITICAL1HIGH133MEDIUM17LOW2
Vulnerabilities
Page 1 of 8
CVE-2017-11826P1HIGHCVSS 7.8KEVPoCv20162017-10-13
CVE-2017-11826 [HIGH] CWE-119 CVE-2017-11826: Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications,
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.
nvd
CVE-2023-21716P1CRITICALCVSS 9.8ExploitedPoCv20162023-02-14
CVE-2023-21716 [CRITICAL] CWE-190 CVE-2023-21716: Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2025-47165P1HIGHCVSS 7.8ExploitedPoCfixed in 16.0.10417.20018≥ 16.0.0.0, < 16.0.10417.200182025-06-10
CVE-2025-47165 [HIGH] CWE-416 CVE-2025-47165: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-27751P3HIGHCVSS 7.8PoC≥ 16.0.0.0, < 16.0.10417.200032025-04-08
CVE-2025-27751 [HIGH] CWE-416 CVE-2025-27751: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2018-0792P3HIGHCVSS 8.8v20162018-01-10
CVE-2018-0792 [HIGH] CWE-787 CVE-2018-0792: Microsoft Word 2016 in Microsoft Office 2016 allows a remote code execution vulnerability due to the
Microsoft Word 2016 in Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0794.
nvd
CVE-2017-8512P3HIGHCVSS 8.8v20162017-06-15
CVE-2017-8512 [HIGH] CVE-2017-8512: A remote code execution vulnerability exists in Microsoft Office when the software fails to properly
A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8509, CVE-2017-8510, CVE-2017-8511, CVE-2017-0260, and CVE-2017-8506.
nvd
CVE-2019-1327P3HIGHCVSS 8.8vunspecified2019-10-10
CVE-2019-1327 [HIGH] CVE-2019-1327: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1331.
nvd
CVE-2020-1446P3HIGHCVSS 8.8v1.02020-07-14
CVE-2020-1446 [HIGH] CVE-2020-1446: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448.
nvd
CVE-2020-1447P3HIGHCVSS 8.8v1.02020-07-14
CVE-2020-1447 [HIGH] CVE-2020-1447: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1448.
nvd
CVE-2020-1448P3HIGHCVSS 8.8v1.02020-07-14
CVE-2020-1448 [HIGH] CVE-2020-1448: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1447.
nvd
CVE-2018-0922P3HIGHCVSS 7.8v20162018-03-14
CVE-2018-0922 [HIGH] CWE-787 CVE-2018-0922: Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2
Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Compatibility Pack SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft Office Word Viewer, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft SharePoint Enterprise Server 2016, Micro
nvd
CVE-2018-0797P3HIGHCVSS 7.8v20162018-01-10
CVE-2018-0797 [HIGH] CWE-787 CVE-2018-0797: Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code executio
Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memory Corruption Vulnerability".
nvd
CVE-2020-1495P3HIGHCVSS 8.8≥ https://aka.ms/OfficeSecurityReleases, < publication2020-08-17
CVE-2020-1495 [HIGH] CVE-2020-1495: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affecte
nvd
CVE-2020-0850P3HIGHCVSS 8.8v1.02020-03-12
CVE-2020-0850 [HIGH] CVE-2020-0850: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0851, CVE-2020-0852, CVE-2020-0855, CVE-2020-0892.
nvd
CVE-2020-1335P3HIGHCVSS 8.8v1.02020-09-11
CVE-2020-1335 [HIGH] CVE-2020-1335: <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affecte
nvd
CVE-2018-8628P3HIGHCVSS 7.8vOffice Online Server2018-12-12
CVE-2018-8628 [HIGH] CVE-2018-8628: A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fail
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft PowerPoint, Microsoft SharePoint, Microsoft PowerPoint Viewer, Office Online Server, Microsoft Sha
nvd
CVE-2017-8501P3HIGHCVSS 7.8v20162017-07-11
CVE-2017-8501 [HIGH] CWE-119 CVE-2017-8501: Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8502.
nvd
CVE-2017-0281P3HIGHCVSS 7.8v20162017-05-12
CVE-2017-0281 [HIGH] CVE-2017-0281: Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2016, Office Online Server 2016,
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2016, Office Online Server 2016, Office Web Apps 2010 SP2,Office Web Apps 2013 SP1, Project Server 2013 SP1, SharePoint Enterprise Server 2013 SP1, SharePoint Enterprise Server 2016, SharePoint Foundation 2013 SP1, Sharepoint Server 2010 SP2, Word 2016, and Skype for Business 2016 allow a remot
nvd
CVE-2025-49697P3HIGHCVSS 8.4fixed in 16.0.10417.20027≥ 16.0.0.0, < 16.0.10417.200272025-07-08
CVE-2025-49697 [HIGH] CWE-122 CVE-2025-49697: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2021-31939P3HIGHCVSS 7.8≥ https://aka.ms/OfficeSecurityReleases, < 16.0.10375.200002021-06-08
CVE-2021-31939 [HIGH] CVE-2021-31939: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd
1 / 8Next →