Msrc Microsoft Office 2013 Service Pack 1 vulnerabilities

142 known vulnerabilities affecting msrc/microsoft_office_2013_service_pack_1.

Total CVEs
142
CISA KEV
11
actively exploited
Public exploits
6
Exploited in wild
12
Severity breakdown
CRITICAL1HIGH124MEDIUM16LOW1

Vulnerabilities

Page 2 of 8
CVE-2021-40471HIGHCVSS 7.82021-10-12
CVE-2021-40471 [HIGH] Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. Microsoft Office Excel: Microsoft Office Excel Microsoft: Microsoft Impact: Remote Code Execution Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A Re
msrc
CVE-2021-40473HIGHCVSS 7.82021-10-12
CVE-2021-40473 [HIGH] Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. Microsoft Office Excel: Microsoft Office Excel Microsoft: Microsoft Impact: Remote Code Execution Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A Re
msrc
CVE-2021-40479HIGHCVSS 7.82021-10-12
CVE-2021-40479 [HIGH] Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. Microsoft Office Excel: Microsoft Office Excel Microsoft: Microsoft Impact: Remote Code Execution Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A Re
msrc
CVE-2021-40472MEDIUMCVSS 5.52021-10-12
CVE-2021-40472 [MEDIUM] Microsoft Excel Information Disclosure Vulnerability Microsoft Excel Information Disclosure Vulnerability FAQ: What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory. FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. Microsoft Office Excel: Microsoft Office Excel Micro
msrc
CVE-2021-40454MEDIUMCVSS 5.52021-10-12
CVE-2021-40454 [MEDIUM] Rich Text Edit Control Information Disclosure Vulnerability Rich Text Edit Control Information Disclosure Vulnerability FAQ: What type of information could be disclosed by this vulnerability? An attacker that successfully exploited this vulnerability could recover cleartext passwords from memory. Rich Text Edit Control: Rich Text Edit Control Microsoft: Microsoft Impact: Information Disclosure Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release
msrc
CVE-2021-38646HIGHCVSS 7.8KEV2021-09-14
CVE-2021-38646 [HIGH] Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. Microsoft Office Access: Microsoft Office Access Microsoft: Microsoft Impact: Remote Code Execution Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;O
msrc
CVE-2021-38650HIGHCVSS 7.62021-09-14
CVE-2021-38650 [HIGH] Microsoft Office Spoofing Vulnerability Microsoft Office Spoofing Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. Microsoft Office: Microsoft Office Microsoft: Microsoft Impact: Spoofing Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A Remediation: Click to Run Remediation: Release Not
msrc
CVE-2021-38658HIGHCVSS 7.82021-09-14
CVE-2021-38658 [HIGH] Microsoft Office Graphics Remote Code Execution Vulnerability Microsoft Office Graphics Remote Code Execution Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. Microsoft Office: Microsoft Office Microsoft: Microsoft Impact: Remote Code Execution Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS
msrc
CVE-2021-34469HIGHCVSS 8.22021-07-13
CVE-2021-34469 [HIGH] Microsoft Office Security Feature Bypass Vulnerability Microsoft Office Security Feature Bypass Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided co
msrc
CVE-2021-31939HIGHCVSS 7.82021-06-08
CVE-2021-31939 [HIGH] Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? Exploitation of the vulnerability requires that a user open a specially crafted file. In an email attack scenario, an attacker could exploit th
msrc
CVE-2021-31941HIGHCVSS 7.82021-06-08
CVE-2021-31941 [HIGH] Microsoft Office Graphics Remote Code Execution Vulnerability Microsoft Office Graphics Remote Code Execution Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? Exploitation of the vulnerability requires that a user open a specially crafted file. In an email attack scenario, an attac
msrc
CVE-2021-31940HIGHCVSS 7.82021-06-08
CVE-2021-31940 [HIGH] Microsoft Office Graphics Remote Code Execution Vulnerability Microsoft Office Graphics Remote Code Execution Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? Exploitation of the vulnerability requires that a user open a specially crafted file. In an email attack scenario, an attac
msrc
CVE-2021-31180HIGHCVSS 7.82021-05-11
CVE-2021-31180 [HIGH] Microsoft Office Graphics Remote Code Execution Vulnerability Microsoft Office Graphics Remote Code Execution Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? Exploitation of the vulnerability requires that a user open a specially crafted file. In an email attack scenario, an attac
msrc
CVE-2021-31175HIGHCVSS 7.82021-05-11
CVE-2021-31175 [HIGH] Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? Exploitation of the vulnerability requires that a user open a specially crafted file. In an email attack scenario, an attacker could exploit
msrc
CVE-2021-28455HIGHCVSS 8.82021-05-11
CVE-2021-28455 [HIGH] Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. FAQ: How do the security updates address this vulnerability? The security updates address the vulnerability by providing the ability to configure the Jet Red Data
msrc
CVE-2021-31179HIGHCVSS 7.82021-05-11
CVE-2021-31179 [HIGH] Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? Exploitation of the vulnerability requires that a user open a specially crafted file. In an email attack scenario, an attacker could exploit
msrc
CVE-2021-31176HIGHCVSS 7.82021-05-11
CVE-2021-31176 [HIGH] Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Excel. In an email
msrc
CVE-2021-31174MEDIUMCVSS 5.52021-05-11
CVE-2021-31174 [MEDIUM] Microsoft Excel Information Disclosure Vulnerability Microsoft Excel Information Disclosure Vulnerability FAQ: What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory. FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. Microsoft Office Excel: Microsoft Office Excel Micro
msrc
CVE-2021-31178MEDIUMCVSS 5.52021-05-11
CVE-2021-31178 [MEDIUM] Microsoft Office Information Disclosure Vulnerability Microsoft Office Information Disclosure Vulnerability FAQ: What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory. FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. Microsoft Office Excel: Microsoft Office Excel Mic
msrc
CVE-2021-28454HIGHCVSS 7.82021-04-13
CVE-2021-28454 [HIGH] Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Excel. In an email a
msrc