Microsoft Word vulnerabilities
265 known vulnerabilities affecting microsoft/word.
Total CVEs
265
CISA KEV
10
actively exploited
Public exploits
20
Exploited in wild
18
Severity breakdown
CRITICAL79HIGH142MEDIUM42LOW2
Vulnerabilities
Page 9 of 14
CVE-2025-62558P3HIGHCVSS 7.8v20162025-12-09
CVE-2025-62558 [HIGH] CWE-416 CVE-2025-62558: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-62559P3HIGHCVSS 7.8v20162025-12-09
CVE-2025-62559 [HIGH] CWE-416 CVE-2025-62559: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-55038P3HIGHCVSS 7.8v20162026-07-14
CVE-2026-55038 [HIGH] CWE-121 CVE-2026-55038: Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-55127P3HIGHCVSS 7.8v20162026-07-14
CVE-2026-55127 [HIGH] CWE-122 CVE-2026-55127: Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-55055P3HIGHCVSS 7.8v20162026-07-14
CVE-2026-55055 [HIGH] CWE-121 CVE-2026-55055: Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-55128P3HIGHCVSS 7.8v20162026-07-14
CVE-2026-55128 [HIGH] CWE-416 CVE-2026-55128: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-55130P3HIGHCVSS 7.8v20162026-07-14
CVE-2026-55130 [HIGH] CWE-122 CVE-2026-55130: Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-55032P3HIGHCVSS 7.8v20162026-07-14
CVE-2026-55032 [HIGH] CWE-416 CVE-2026-55032: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-55134P3HIGHCVSS 7.8v20162026-07-14
CVE-2026-55134 [HIGH] CWE-121 CVE-2026-55134: Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2020-0892P3HIGHCVSS 7.8v2010v2013+1 more2020-03-12
CVE-2020-0892 [HIGH] CVE-2020-0892: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0852, CVE-2020-0855.
nvd
CVE-2004-0963P3CRITICALCVSS 10.0v20022005-02-09
CVE-2004-0963 [CRITICAL] CVE-2004-0963: Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remot
Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that ca
nvd
CVE-2026-55132P3HIGHCVSS 7.8v20162026-07-14
CVE-2026-55132 [HIGH] CWE-415 CVE-2026-55132: Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-59222P3HIGHCVSS 7.8v20162025-10-14
CVE-2025-59222 [HIGH] CWE-416 CVE-2025-59222: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2016-3279P3MEDIUMCVSS 5.5v2010v2013+1 more2016-07-13
CVE-2016-3279 [MEDIUM] CWE-254 CVE-2016-3279: Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, Power
Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Excel 2016, Word 2016, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via
nvd
CVE-2007-1202P3MEDIUMCVSS 6.8v2000v2002+2 more2007-05-08
CVE-2007-1202 [MEDIUM] CWE-20 CVE-2007-1202: Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite
Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly parse certain rich text "property strings of certain control words," which allows user-assisted remote attackers to trigger heap corruption and execute arbitrary code, aka the "Word RTF Parsing Vulnerability."
nvd
CVE-2024-49033P3HIGHCVSS 7.5v20162024-11-12
CVE-2024-49033 [HIGH] CWE-20 CVE-2024-49033: Microsoft Word Security Feature Bypass Vulnerability
Microsoft Word Security Feature Bypass Vulnerability
nvd
CVE-2025-47169P3HIGHCVSS 7.8v20162025-06-10
CVE-2025-47169 [HIGH] CWE-122 CVE-2025-47169: Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-53738P3HIGHCVSS 7.8v20162025-08-12
CVE-2025-53738 [HIGH] CWE-416 CVE-2025-53738: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-55033P3HIGHCVSS 7.8v20162026-07-14
CVE-2026-55033 [HIGH] CWE-122 CVE-2026-55033: Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute c
Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2021-40486P3HIGHCVSS 7.8v2013v20162021-10-13
CVE-2021-40486 [HIGH] CVE-2021-40486: Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
nvd