cbcvebase.

Microsoft Word vulnerabilities

265 known vulnerabilities affecting microsoft/word.

Total CVEs
265
CISA KEV
10
actively exploited
Public exploits
20
Exploited in wild
18
Severity breakdown
CRITICAL79HIGH142MEDIUM42LOW2

Vulnerabilities

Page 11 of 14
CVE-2016-7291P3HIGHCVSS 7.1v2007v20102016-12-20
CVE-2016-7291 [HIGH] CVE-2016-7291: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office
nvd
CVE-2016-7290P3HIGHCVSS 7.1v2007v20102016-12-20
CVE-2016-7290 [HIGH] CWE-125 CVE-2016-7290: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft
nvd
CVE-2016-7268P3HIGHCVSS 7.1v20072016-12-20
CVE-2016-7268 [HIGH] CWE-125 CVE-2016-7268: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, a
nvd
CVE-2026-20948P3HIGHCVSS 7.8v20162026-01-13
CVE-2026-20948 [HIGH] CWE-822 CVE-2026-20948: Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute co Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-26133P3HIGHCVSS 7.1fixed in 2.106.2fixed in 16.0.19822.200382026-03-16
CVE-2026-26133 [HIGH] CWE-77 CVE-2026-26133: AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2018-8310P3HIGHCVSS 7.5v2010-sp2v2013-sp1+1 more2018-07-11
CVE-2018-8310 [HIGH] CVE-2018-8310: A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails, aka "Microsoft Office Tampering Vulnerability." This affects Microsoft Word, Microsoft Office.
nvd
CVE-2021-31177P3HIGHCVSS 7.8v2013v20162021-05-11
CVE-2021-31177 [HIGH] CWE-416 CVE-2021-31177: Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2022-21842P3HIGHCVSS 7.8v20162022-01-11
CVE-2022-21842 [HIGH] CVE-2022-21842: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2021-34452P3HIGHCVSS 7.8v20162021-07-16
CVE-2021-34452 [HIGH] CVE-2021-34452: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2017-0105P3MEDIUMCVSS 5.5v20072017-03-17
CVE-2017-0105 [MEDIUM] CWE-200 CVE-2017-0105: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Office Compatibility Pac Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from out-of-bound memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulne
nvd
CVE-2013-3160P3MEDIUMCVSS 5.0v2003v20072013-09-11
CVE-2013-3160 [MEDIUM] CWE-200 CVE-2013-3160: Microsoft Office 2003 SP3 and 2007 SP3, Word 2003 SP3 and 2007 SP3, and Word Viewer allow remote att Microsoft Office 2003 SP3 and 2007 SP3, Word 2003 SP3 and 2007 SP3, and Word Viewer allow remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka "XML External Entities Resolution Vulnerability."
nvd
CVE-2021-31180P3HIGHCVSS 7.8v2013v20162021-05-11
CVE-2021-31180 [HIGH] CVE-2021-31180: Microsoft Office Graphics Remote Code Execution Vulnerability Microsoft Office Graphics Remote Code Execution Vulnerability
nvd
CVE-2024-20673P3HIGHCVSS 7.8v20162024-02-13
CVE-2024-20673 [HIGH] CWE-693 CVE-2024-20673: Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2023-29335P3HIGHCVSS 7.5v2013v20162023-05-09
CVE-2023-29335 [HIGH] CWE-20 CVE-2023-29335: Microsoft Word Security Feature Bypass Vulnerability Microsoft Word Security Feature Bypass Vulnerability
nvd
CVE-2002-1056P3HIGHCVSS 7.5v2000v20022002-05-16
CVE-2002-1056 [HIGH] CVE-2002-1056: Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.
nvd
CVE-2000-0788P3CRITICALCVSS 10.0v20002000-10-20
CVE-2000-0788 [CRITICAL] CVE-2000-0788: The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) s The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow an attacker to execute arbitrary commands.
nvd
CVE-2022-41061P3HIGHCVSS 7.8v2013v20162022-11-09
CVE-2022-41061 [HIGH] CWE-94 CVE-2022-41061: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2016-3234P3MEDIUMCVSS 5.5v2007v20102016-06-16
CVE-2016-3234 [MEDIUM] CWE-200 CVE-2016-3234: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to obtain sensitive information from process memory via
nvd
CVE-2023-36762P3HIGHCVSS 7.3v20162023-09-12
CVE-2023-36762 [HIGH] CWE-20 CVE-2023-36762: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2025-62555P3HIGHCVSS 7.0v20162025-12-09
CVE-2025-62555 [HIGH] CWE-416 CVE-2025-62555: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
Microsoft Word vulnerabilities | cvebase