cbcvebase.

Msrc Microsoft Excel 2013 Service Pack 1 vulnerabilities

131 known vulnerabilities affecting msrc/microsoft_excel_2013_service_pack_1.

Total CVEs
131
CISA KEV
3
actively exploited
Public exploits
3
Exploited in wild
7
Severity breakdown
HIGH121MEDIUM10

Vulnerabilities

Page 1 of 7
CVE-2023-36766HIGHCVSS 7.82023-09-12
CVE-2023-36766 [HIGH] CWE-125 Microsoft Excel Information Disclosure Vulnerability Microsoft Excel Information Disclosure Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is information disclosure? The attack itself is carried out locally. For example, when the score indicates that the Attack Vector is Local
msrc
CVE-2023-36896HIGHCVSS 7.82023-08-08
CVE-2023-36896 [HIGH] CWE-122 Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability FAQ: Are the updates for the Microsoft Office for Mac currently available? The security update for Microsoft Office 2019 for Mac and Microsoft Office LTSC for Mac 2021 are not immediately available. The updates will be released as soon as possible, and when they are available, customers will be notified via a revision to this CVE information. FAQ: According to t
msrc
CVE-2023-33162MEDIUMCVSS 5.52023-07-11
CVE-2023-33162 [MEDIUM] CWE-125 Microsoft Excel Information Disclosure Vulnerability Microsoft Excel Information Disclosure Vulnerability FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is information disclosure? The attack itself is carried out locally. For example, when the score indicates that the Attack Vector is Local and User Interaction is Required, this could describe an exploit in which an attacker, through social engineer
msrc
CVE-2023-32029HIGHCVSS 7.82023-06-13
CVE-2023-32029 [HIGH] CWE-125 Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim
msrc
CVE-2023-33137HIGHCVSS 7.8PoC2023-06-13
CVE-2023-33137 [HIGH] CWE-415 Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim
msrc
CVE-2023-33133HIGHCVSS 7.82023-06-13
CVE-2023-33133 [HIGH] CWE-122 Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim
msrc
CVE-2023-24953HIGHCVSS 7.82023-05-09
CVE-2023-24953 [HIGH] CWE-416 Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability FAQ: Are the updates for the Microsoft Office for Mac currently available? The security update for Microsoft Office 2019 for Mac and Microsoft Office LTSC for Mac 2021 are not immediately available. The updates will be released as soon as possible, and when they are available, customers will be notified via a revision to this CVE information. FAQ: According to t
msrc
CVE-2023-23399HIGHCVSS 7.8PoC2023-03-14
CVE-2023-23399 [HIGH] CWE-125 Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. For example, when the score indic
msrc
CVE-2023-23398HIGHCVSS 7.12023-03-14
CVE-2023-23398 [HIGH] Microsoft Excel Spoofing Vulnerability Microsoft Excel Spoofing Vulnerability FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Excel and click the security warning prompt to "Enable Content". In an email attack scenario, an attacker could exploit the vulnerability by sending the specia
msrc
CVE-2022-41063HIGHCVSS 7.82022-11-08
CVE-2022-41063 [HIGH] Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Ar
msrc
CVE-2022-41106HIGHCVSS 8.82022-11-08
CVE-2022-41106 [HIGH] Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Ar
msrc
CVE-2022-41104MEDIUMCVSS 5.52022-11-08
CVE-2022-41104 [MEDIUM] Microsoft Excel Security Feature Bypass Vulnerability Microsoft Excel Security Feature Bypass Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Excel. In an e
msrc
CVE-2022-33631HIGHCVSS 7.32022-08-09
CVE-2022-33631 [HIGH] Microsoft Excel Security Feature Bypass Vulnerability Microsoft Excel Security Feature Bypass Vulnerability FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Excel. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user
msrc
CVE-2022-30173HIGHCVSS 7.82022-06-14
CVE-2022-30173 [HIGH] Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? Exploitation of the vulnerability requires that a user open a specially crafted file. In an email attack scenario, an attacker could exploit th
msrc
CVE-2022-29110HIGHCVSS 7.82022-05-10
CVE-2022-29110 [HIGH] Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. For example, when the score indicates tha
msrc
CVE-2022-26901HIGHCVSS 7.82022-04-12
CVE-2022-26901 [HIGH] Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Ar
msrc
CVE-2022-22716MEDIUMCVSS 5.52022-02-08
CVE-2022-22716 [MEDIUM] Microsoft Excel Information Disclosure Vulnerability Microsoft Excel Information Disclosure Vulnerability FAQ: Are the updates for the Microsoft Office for Mac currently available? The security update for Microsoft Office 2019 for Mac and Microsoft Office LTSC for Mac 2021 are not immediately available. The updates will be released as soon as possible, and when they are available, customers will be notified via a revision to this CVE information. FAQ: Is the Preview Pan
msrc
CVE-2022-21840HIGHCVSS 8.82022-01-11
CVE-2022-21840 [HIGH] Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? Exploitation of the vulnerability requires that a user open a specially crafted file. In an email attack scenario, an attacker could exploit
msrc
CVE-2021-43256HIGHCVSS 7.82021-12-14
CVE-2021-43256 [HIGH] Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. Microsoft Office Excel: Microsoft Office Excel Microsoft: Microsoft Impact: Remote Code Execution Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A Re
msrc
CVE-2021-42292HIGHCVSS 7.8KEV2021-11-09
CVE-2021-42292 [HIGH] Microsoft Excel Security Feature Bypass Vulnerability Microsoft Excel Security Feature Bypass Vulnerability FAQ: Are the updates for the Microsoft Office for Mac currently available? The security update for Microsoft Office 2019 for Mac and Microsoft Office LTSC for Mac 2021 are not immediately available. The updates will be released as soon as possible, and when they are available, customers will be notified via a revision to this CVE information. FAQ: Is the Preview Pan
msrc