Microsoft Word vulnerabilities

243 known vulnerabilities affecting microsoft/word.

Total CVEs
243
CISA KEV
10
actively exploited
Public exploits
16
Exploited in wild
11
Severity breakdown
CRITICAL79HIGH127MEDIUM35LOW2

Vulnerabilities

Page 2 of 13
CVE-2025-29816HIGHCVSS 7.5v20162025-04-08
CVE-2025-29816 [HIGH] CWE-349 CVE-2025-29816: Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a secur Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2025-24078HIGHCVSS 7.0v20162025-03-11
CVE-2025-24078 [HIGH] CWE-416 CVE-2025-24078: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-24079HIGHCVSS 7.8v20162025-03-11
CVE-2025-24079 [HIGH] CWE-416 CVE-2025-24079: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2024-41165CRITICALCVSS 9.1v16.83v16.83 for macOS2024-12-18
CVE-2024-41165 [CRITICAL] CWE-347 CVE-2024-41165: A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted libr A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.
cvelistv5nvd
CVE-2024-49065MEDIUMCVSS 5.5v20162024-12-12
CVE-2024-49065 [MEDIUM] CWE-125 CVE-2024-49065: Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2024-49033HIGHCVSS 7.5v20162024-11-12
CVE-2024-49033 [HIGH] CWE-20 CVE-2024-49033: Microsoft Word Security Feature Bypass Vulnerability Microsoft Word Security Feature Bypass Vulnerability
nvd
CVE-2024-21379HIGHCVSS 7.8v20162024-02-13
CVE-2024-21379 [HIGH] CWE-190 CVE-2024-21379: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2024-20673HIGHCVSS 7.8v20162024-02-13
CVE-2024-20673 [HIGH] CWE-693 CVE-2024-20673: Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2023-36762HIGHCVSS 7.3v20162023-09-12
CVE-2023-36762 [HIGH] CWE-20 CVE-2023-36762: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2023-36761MEDIUMCVSS 6.5KEVv2013v20162023-09-12
CVE-2023-36761 [MEDIUM] CWE-20 CVE-2023-36761: Microsoft Word Information Disclosure Vulnerability Microsoft Word Information Disclosure Vulnerability
nvd
CVE-2023-33150CRITICALCVSS 9.6v2013v20162023-07-11
CVE-2023-33150 [CRITICAL] CWE-693 CVE-2023-33150: Microsoft Office Security Feature Bypass Vulnerability Microsoft Office Security Feature Bypass Vulnerability
nvd
CVE-2023-29335HIGHCVSS 7.5v2013v20162023-05-09
CVE-2023-29335 [HIGH] CWE-20 CVE-2023-29335: Microsoft Word Security Feature Bypass Vulnerability Microsoft Word Security Feature Bypass Vulnerability
nvd
CVE-2023-21716CRITICALCVSS 9.8Exploitedv20132023-02-14
CVE-2023-21716 [CRITICAL] CWE-190 CVE-2023-21716: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2022-41061HIGHCVSS 7.8v2013v20162022-11-09
CVE-2022-41061 [HIGH] CWE-94 CVE-2022-41061: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2022-41060MEDIUMCVSS 5.5v2013v20162022-11-09
CVE-2022-41060 [MEDIUM] CVE-2022-41060: Microsoft Word Information Disclosure Vulnerability Microsoft Word Information Disclosure Vulnerability
nvd
CVE-2022-41103MEDIUMCVSS 5.5v2013v20162022-11-09
CVE-2022-41103 [MEDIUM] CVE-2022-41103: Microsoft Word Information Disclosure Vulnerability Microsoft Word Information Disclosure Vulnerability
nvd
CVE-2022-29107MEDIUMCVSS 5.5v2013v20162022-05-10
CVE-2022-29107 [MEDIUM] CVE-2022-29107: Microsoft Office Security Feature Bypass Vulnerability Microsoft Office Security Feature Bypass Vulnerability
nvd
CVE-2022-21842HIGHCVSS 7.8v20162022-01-11
CVE-2022-21842 [HIGH] CVE-2022-21842: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2021-40486HIGHCVSS 7.8v2013v20162021-10-13
CVE-2021-40486 [HIGH] CVE-2021-40486: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2021-34452HIGHCVSS 7.8v20162021-07-16
CVE-2021-34452 [HIGH] CVE-2021-34452: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd