Msrc Microsoft Office 2016 vulnerabilities

218 known vulnerabilities affecting msrc/microsoft_office_2016.

Total CVEs
218
CISA KEV
13
actively exploited
Public exploits
8
Exploited in wild
13
Severity breakdown
CRITICAL3HIGH189MEDIUM24LOW2

Vulnerabilities

Page 2 of 11
CVE-2025-47173HIGHCVSS 7.82025-06-10
CVE-2025-47173 [HIGH] CWE-641 Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability Description: Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally. FAQ: Are the updates for the Microsoft 365 for Office currently available? The security update for Microsoft 365 are not immediately available. The updates will be released as soon as possible, and when they are available, customers will be notif
msrc
CVE-2025-47162HIGHCVSS 8.42025-06-10
CVE-2025-47162 [HIGH] CWE-122 Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability Description: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes re
msrc
CVE-2025-47164HIGHCVSS 8.42025-06-10
CVE-2025-47164 [HIGH] CWE-416 Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability Description: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. FAQ: Is the Preview Pane an attack vector for this vulnerability? Yes, the Preview Pane is an attack vector. FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The wor
msrc
CVE-2025-47953HIGHCVSS 8.42025-06-10
CVE-2025-47953 [HIGH] CWE-641 Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability Description: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. FAQ: Are the updates for the Microsoft 365 for Office currently available? The security update for Microsoft 365 are not immediately available. The updates will be released as soon as possible, and when they are available, customers will be notified via a r
msrc
CVE-2025-47167HIGHCVSS 8.42025-06-10
CVE-2025-47167 [HIGH] CWE-843 Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability Description: Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. FAQ: Is the Preview Pane an attack vector for this vulnerability? Yes, the Preview Pane is an attack vector. FAQ: Are the updates for the Microsoft 365 for Office currently available? The security update for M
msrc
CVE-2025-30386HIGHCVSS 8.42025-05-13
CVE-2025-30386 [HIGH] CWE-416 Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability Description: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. FAQ: How could an attacker exploit this vulnerability? To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of a
msrc
CVE-2025-30377HIGHCVSS 8.42025-05-13
CVE-2025-30377 [HIGH] CWE-416 Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability Description: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. FAQ: Is the Preview Pane an attack vector for this vulnerability? Yes, the Preview Pane is an attack vector. FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The wor
msrc
CVE-2025-29979HIGHCVSS 7.82025-05-13
CVE-2025-29979 [HIGH] CWE-122 Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability Description: Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code
msrc
CVE-2025-29792HIGHCVSS 7.32025-04-08
CVE-2025-29792 [HIGH] CWE-416 Microsoft Office Elevation of Privilege Vulnerability Microsoft Office Elevation of Privilege Vulnerability Description: Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. FAQ: How could an attacker exploit this vulnerability? To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take contro
msrc
CVE-2025-29791HIGHCVSS 7.82025-04-08
CVE-2025-29791 [HIGH] CWE-843 Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability Description: Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? An attacker must send a user a malicious Office file and convince them to open it. FAQ: Accordi
msrc
CVE-2025-29820HIGHCVSS 7.82025-04-08
CVE-2025-29820 [HIGH] CWE-416 Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability Description: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to a
msrc
CVE-2025-26642HIGHCVSS 7.82025-04-08
CVE-2025-26642 [HIGH] CWE-125 Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability Description: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
msrc
CVE-2025-27745HIGHCVSS 7.82025-04-08
CVE-2025-27745 [HIGH] CWE-416 Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability Description: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as
msrc
CVE-2025-27749HIGHCVSS 7.82025-04-08
CVE-2025-27749 [HIGH] CWE-416 Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability Description: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as
msrc
CVE-2025-27746HIGHCVSS 7.82025-04-08
CVE-2025-27746 [HIGH] CWE-416 Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability Description: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as
msrc
CVE-2025-29816HIGHCVSS 7.52025-04-08
CVE-2025-29816 [HIGH] CWE-349 Microsoft Word Security Feature Bypass Vulnerability Microsoft Word Security Feature Bypass Vulnerability Description: Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network. FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. FAQ: There are multiple update packages available for some of the affected software. Do I need to install al
msrc
CVE-2025-27748HIGHCVSS 7.82025-04-08
CVE-2025-27748 [HIGH] CWE-416 Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability Description: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as
msrc
CVE-2025-27744HIGHCVSS 7.82025-04-08
CVE-2025-27744 [HIGH] CWE-284 Microsoft Office Elevation of Privilege Vulnerability Microsoft Office Elevation of Privilege Vulnerability Description: Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally. FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully e
msrc
CVE-2025-27752HIGHCVSS 7.82025-04-08
CVE-2025-27752 [HIGH] CWE-122 Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability Description: Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remote in the title refers to the location of the attacker. This type of exploit is sometime
msrc
CVE-2025-24083HIGHCVSS 7.82025-03-11
CVE-2025-24083 [HIGH] CWE-822 Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability Description: Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code
msrc