Microsoft Word vulnerabilities
265 known vulnerabilities affecting microsoft/word.
Total CVEs
265
CISA KEV
10
actively exploited
Public exploits
20
Exploited in wild
18
Severity breakdown
CRITICAL79HIGH142MEDIUM42LOW2
Vulnerabilities
Page 7 of 14
CVE-2020-0760P3HIGHCVSS 8.8v2010v2013+1 more2020-04-15
CVE-2020-0760 [HIGH] CVE-2020-0760: A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type l
A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0991.
nvd
CVE-2018-8430P3HIGHCVSS 7.8v20162018-09-13
CVE-2018-8430 [HIGH] CVE-2018-8430: A remote code execution vulnerability exists in Microsoft Word if a user opens a specially crafted P
A remote code execution vulnerability exists in Microsoft Word if a user opens a specially crafted PDF file, aka "Word PDF Remote Code Execution Vulnerability." This affects Microsoft Word, Microsoft Office.
nvd
CVE-2016-3317P3HIGHCVSS 7.8v2007v20102016-08-09
CVE-2016-3317 [HIGH] CWE-119 CVE-2016-3317: Microsoft Office 2010 SP2, Word 2007 SP3, Word 2010 SP2, Word for Mac 2011, Word 2016 for Mac, and W
Microsoft Office 2010 SP2, Word 2007 SP3, Word 2010 SP2, Word for Mac 2011, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbitrary code via a crafted file, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2007-1911P4HIGHCVSS 7.1PoCv20072007-04-10
CVE-2007-1911 [HIGH] CVE-2007-1911: Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial
Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU consumption) via crafted documents, as demonstrated by (1) file798-1.doc and (2) file613-1.doc, possibly related to a buffer overflow.
nvd
CVE-2026-40361P3HIGHCVSS 8.4v20162026-05-12
CVE-2026-40361 [HIGH] CWE-416 CVE-2026-40361: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2016-3280P3HIGHCVSS 7.8v2007v2010+1 more2016-07-13
CVE-2016-3280 [HIGH] CWE-119 CVE-2016-3280: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for M
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2017-0254P3HIGHCVSS 7.8v2007v2010+2 more2017-05-12
CVE-2017-0254 [HIGH] CWE-119 CVE-2017-0254: Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Office for Mac 2
Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Office for Mac 2011, Office for Mac 2016, Microsoft Office Web Apps 2010 SP2, Office Web Apps Server 2013 SP1, Word 2013 RT SP1, Word 2013 SP1, Word Automation Services on Microsoft SharePoint Server 2013 SP1, Office Word Viewer, SharePoint Enterprise Server 2016, and Wo
nvd
CVE-2018-0797P3HIGHCVSS 7.8v2007v2010+2 more2018-01-10
CVE-2018-0797 [HIGH] CWE-787 CVE-2018-0797: Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code executio
Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memory Corruption Vulnerability".
nvd
CVE-2023-33150P3CRITICALCVSS 9.6v2013v20162023-07-11
CVE-2023-33150 [CRITICAL] CWE-693 CVE-2023-33150: Microsoft Office Security Feature Bypass Vulnerability
Microsoft Office Security Feature Bypass Vulnerability
nvd
CVE-2018-8157P3HIGHCVSS 7.8vAutomation Services on Microsoft SharePoint Server 2010 Service Pack 2vAutomation Services on Microsoft SharePoint Server 2013 Service Pack 12018-05-09
CVE-2018-8157 [HIGH] CVE-2018-8157: A remote code execution vulnerability exists in Microsoft Office software when the software fails to
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-8158, CVE-2018-8161.
nvd
CVE-2020-0850P3HIGHCVSS 8.8v2013v20162020-03-12
CVE-2020-0850 [HIGH] CVE-2020-0850: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0851, CVE-2020-0852, CVE-2020-0855, CVE-2020-0892.
nvd
CVE-2018-0793P3HIGHCVSS 7.8v2007v2010+2 more2018-01-10
CVE-2018-0793 [HIGH] CVE-2018-0793: Microsoft Outlook 2007, Microsoft Outlook 2010 and Microsoft Outlook 2013 allow a remote code execut
Microsoft Outlook 2007, Microsoft Outlook 2010 and Microsoft Outlook 2013 allow a remote code execution vulnerability due to the way email messages are parsed, aka "Microsoft Outlook Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0791.
nvd
CVE-2018-8161P3HIGHCVSS 7.8v2010-sp2v2013-sp1+1 more2018-05-09
CVE-2018-8161 [HIGH] CVE-2018-8161: A remote code execution vulnerability exists in Microsoft Office software when the software fails to
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Word, Word, Microsoft Office, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8157, CVE-2018-8158.
nvd
CVE-2014-0259P3CRITICALCVSS 9.3v20072014-01-15
CVE-2014-0259 [CRITICAL] CWE-119 CVE-2014-0259: Microsoft Word 2007 SP3 and Office Compatibility Pack SP3 allow remote attackers to execute arbitrar
Microsoft Word 2007 SP3 and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."
nvd
CVE-2026-45458P3HIGHCVSS 8.4v20162026-06-09
CVE-2026-45458 [HIGH] CWE-416 CVE-2026-45458: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2018-0845P3HIGHCVSS 7.8v2007v2010+2 more2018-01-22
CVE-2018-0845 [HIGH] CVE-2018-0845: Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Of
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0805, CVE-2018-0806, and CVE-2018-0807.
nvd
CVE-2016-7235P3HIGHCVSS 7.8v2007v20102016-11-10
CVE-2016-7235 [HIGH] CWE-119 CVE-2016-7235: Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, and Offi
Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2014-0258P3CRITICALCVSS 9.3v2003v20072014-01-15
CVE-2014-0258 [CRITICAL] CWE-119 CVE-2014-0258: Microsoft Word 2003 SP3 and 2007 SP3, Office Compatibility Pack SP3, and Word Viewer allow remote at
Microsoft Word 2003 SP3 and 2007 SP3, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."
nvd
CVE-2018-0812P3HIGHCVSS 7.8v2007v2010+2 more2018-01-10
CVE-2018-0812 [HIGH] CWE-787 CVE-2018-0812: Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Of
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Memory Corruption Vulnerability".
nvd
CVE-2015-2380P3CRITICALCVSS 9.3v2007v2010+1 more2015-07-14
CVE-2015-2380 [CRITICAL] CWE-119 CVE-2015-2380: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, and Word 2013 RT SP1 allow r
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, and Word 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd