Microsoft Word vulnerabilities
265 known vulnerabilities affecting microsoft/word.
Total CVEs
265
CISA KEV
10
actively exploited
Public exploits
20
Exploited in wild
18
Severity breakdown
CRITICAL79HIGH142MEDIUM42LOW2
Vulnerabilities
Page 13 of 14
CVE-2026-41101P4MEDIUMCVSS 5.5fixed in 16.0.19822.201902026-05-12
CVE-2026-41101 [MEDIUM] CWE-284 CVE-2026-41101: Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing l
Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.
nvd
CVE-2026-42832P4MEDIUMCVSS 5.5fixed in 16.0.19822.201902026-05-12
CVE-2026-42832 [MEDIUM] CWE-284 CVE-2026-42832: Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing loca
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
nvd
CVE-2020-1445P4MEDIUMCVSS 5.5v2010v2013+1 more2020-07-14
CVE-2020-1445 [MEDIUM] CVE-2020-1445: An information disclosure vulnerability exists when Microsoft Office improperly discloses the conten
An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1342.
nvd
CVE-2022-29107P4MEDIUMCVSS 5.5v2013v20162022-05-10
CVE-2022-29107 [MEDIUM] CVE-2022-29107: Microsoft Office Security Feature Bypass Vulnerability
Microsoft Office Security Feature Bypass Vulnerability
nvd
CVE-2026-55124P4MEDIUMCVSS 5.5v20162026-07-14
CVE-2026-55124 [MEDIUM] CWE-20 CVE-2026-55124: Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attac
Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-55142P4MEDIUMCVSS 5.5v20162026-07-14
CVE-2026-55142 [MEDIUM] CWE-197 CVE-2026-55142: Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose inform
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-55050P4MEDIUMCVSS 5.5v20162026-07-14
CVE-2026-55050 [MEDIUM] CWE-125 CVE-2026-55050: Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
CVE-2020-1583P4MEDIUMCVSS 5.5v2010v2013+1 more2020-08-17
CVE-2020-1583 [MEDIUM] CVE-2020-1583: An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents
An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data.
To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mus
nvd
CVE-2020-1503P4MEDIUMCVSS 5.5v2010v2013+1 more2020-08-17
CVE-2020-1503 [MEDIUM] CVE-2020-1503: An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents
An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data.
To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mus
nvd
CVE-2020-17020P4MEDIUMCVSS 5.5v2010v2013+1 more2020-11-11
CVE-2020-17020 [MEDIUM] CVE-2020-17020: Microsoft Word Security Feature Bypass Vulnerability
Microsoft Word Security Feature Bypass Vulnerability
nvd
CVE-2024-49065P4MEDIUMCVSS 5.5v20162024-12-12
CVE-2024-49065 [MEDIUM] CWE-125 CVE-2024-49065: Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2020-1229P4MEDIUMCVSS 4.3v2010v2013+1 more2020-06-09
CVE-2020-1229 [MEDIUM] CVE-2020-1229: A security feature bypass vulnerability exists in Microsoft Outlook when Office fails to enforce sec
A security feature bypass vulnerability exists in Microsoft Outlook when Office fails to enforce security settings configured on a system, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'.
nvd
CVE-2026-40421P4MEDIUMCVSS 4.3v20162026-05-12
CVE-2026-40421 [MEDIUM] CWE-73 CVE-2026-40421: Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
CVE-2008-6063P4MEDIUMCVSS 4.3v20072009-02-05
CVE-2008-6063 [MEDIUM] CWE-200 CVE-2008-6063: Microsoft Word 2007, when the "Save as PDF" add-on is enabled, places an absolute pathname in the Su
Microsoft Word 2007, when the "Save as PDF" add-on is enabled, places an absolute pathname in the Subject field during an "Email as PDF" operation, which allows remote attackers to obtain sensitive information such as the sender's account name and a Temporary Internet Files subdirectory name.
nvd
CVE-2001-0628P4HIGHCVSS 7.2v20002001-08-14
CVE-2001-0628 [HIGH] CVE-2001-0628: Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attack
Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user.
nvd
CVE-2000-0088P4HIGHCVSS 7.2v97v98+1 more2000-01-20
CVE-2000-0088 [HIGH] CVE-2000-0088: Buffer overflow in the conversion utilities for Japanese, Korean and Chinese Word 5 documents allows
Buffer overflow in the conversion utilities for Japanese, Korean and Chinese Word 5 documents allows an attacker to execute commands, aka the "Malformed Conversion Data" vulnerability.
nvd
CVE-2000-0765P4MEDIUMCVSS 5.1v20002000-10-20
CVE-2000-0765 [MEDIUM] CVE-2000-0765: Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbit
Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability.
nvd
CVE-2022-41103P4MEDIUMCVSS 5.5v2013v20162022-11-09
CVE-2022-41103 [MEDIUM] CVE-2022-41103: Microsoft Word Information Disclosure Vulnerability
Microsoft Word Information Disclosure Vulnerability
nvd
CVE-1999-0354P4HIGHCVSS 7.5v971999-11-01
CVE-1999-0354 [HIGH] CVE-1999-0354: Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the
Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message.
nvd
CVE-2010-3200P4MEDIUMCVSS 4.3v20032010-09-20
CVE-2010-3200 [MEDIUM] CVE-2010-3200: MSO.dll in Microsoft Word 2003 SP3 11.8326.11.8324 allows remote attackers to cause a denial of serv
MSO.dll in Microsoft Word 2003 SP3 11.8326.11.8324 allows remote attackers to cause a denial of service (NULL pointer dereference and multiple-instance application crash) via a crafted buffer in a Word document, as demonstrated by word_crash_11.8326.8324_poc.doc.
nvd