Office
by Microsoft
CVEs (1,301)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36568 | Hig | 0.46 | 7.0 | 0.00 | Oct 10, 2023 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | ||
| CVE-2023-36565 | Hig | 0.46 | 7.0 | 0.00 | Oct 10, 2023 | Microsoft Office Graphics Elevation of Privilege Vulnerability | ||
| CVE-2023-33152 | Hig | 0.46 | 7.0 | 0.01 | Jul 11, 2023 | Microsoft ActiveX Remote Code Execution Vulnerability | ||
| CVE-2023-23398 | Hig | 0.46 | 7.1 | 0.01 | Mar 14, 2023 | Microsoft Excel Spoofing Vulnerability | ||
| CVE-2023-21741 | Hig | 0.46 | 7.1 | 0.02 | Jan 10, 2023 | Microsoft Office Visio Information Disclosure Vulnerability | ||
| CVE-2021-28452 | Hig | 0.46 | 7.1 | 0.01 | Apr 13, 2021 | Microsoft Outlook Memory Corruption Vulnerability | ||
| CVE-2021-27055 | Hig | 0.46 | 7.0 | 0.02 | Mar 11, 2021 | Microsoft Visio Security Feature Bypass Vulnerability | ||
| CVE-2020-16934 | Hig | 0.46 | 7.0 | 0.03 | Oct 16, 2020 | An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files. An attacker who successfully exploited the vulnerability could elevate privileges. To exploit this vulnerability, an attacker would need to… | ||
| CVE-2020-16933 | Hig | 0.46 | 7.0 | 0.03 | Oct 16, 2020 | A security feature bypass vulnerability exists in Microsoft Word software when it fails to properly handle .LNK files. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user.… | ||
| CVE-2023-36413 | Med | 0.45 | 6.5 | 0.30 | Nov 14, 2023 | Microsoft Office Security Feature Bypass Vulnerability | ||
| CVE-2025-53736 | Med | 0.44 | 6.8 | 0.01 | Aug 12, 2025 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2025-21357 | Med | 0.44 | 6.7 | 0.01 | Jan 14, 2025 | Microsoft Outlook Remote Code Execution Vulnerability | ||
| CVE-2024-38173 | Med | 0.44 | 6.7 | 0.01 | Aug 13, 2024 | Microsoft Outlook Remote Code Execution Vulnerability | ||
| CVE-2023-35636 | Med | 0.44 | 6.5 | 0.18 | Dec 12, 2023 | Microsoft Outlook Information Disclosure Vulnerability | ||
| CVE-2023-33153 | Med | 0.44 | 6.8 | 0.01 | Jul 11, 2023 | Microsoft Outlook Remote Code Execution Vulnerability | ||
| CVE-2020-17063 | Med | 0.44 | 6.8 | 0.02 | Nov 11, 2020 | Microsoft Office Online Spoofing Vulnerability | ||
| CVE-2016-7257 | Med | 0.44 | 6.5 | 0.23 | Dec 20, 2016 | The GDI component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office for Mac 2011, and Office 2016 for Mac allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI Information Disclosure… | ||
| CVE-2016-7233 | Med | 0.44 | 6.5 | 0.22 | Nov 10, 2016 | Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information… | ||
| CVE-2023-33151 | Med | 0.43 | 6.5 | 0.03 | Jul 11, 2023 | Microsoft Outlook Spoofing Vulnerability | ||
| CVE-2020-17119 | Med | 0.43 | 6.5 | 0.04 | Dec 10, 2020 | Microsoft Outlook Information Disclosure Vulnerability |
- risk 0.46cvss 7.0epss 0.00
Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Microsoft Office Graphics Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Microsoft ActiveX Remote Code Execution Vulnerability
- risk 0.46cvss 7.1epss 0.01
Microsoft Excel Spoofing Vulnerability
- risk 0.46cvss 7.1epss 0.02
Microsoft Office Visio Information Disclosure Vulnerability
- risk 0.46cvss 7.1epss 0.01
Microsoft Outlook Memory Corruption Vulnerability
- risk 0.46cvss 7.0epss 0.02
Microsoft Visio Security Feature Bypass Vulnerability
- risk 0.46cvss 7.0epss 0.03
An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files. An attacker who successfully exploited the vulnerability could elevate privileges. To exploit this vulnerability, an attacker would need to…
- risk 0.46cvss 7.0epss 0.03
A security feature bypass vulnerability exists in Microsoft Word software when it fails to properly handle .LNK files. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user.…
- risk 0.45cvss 6.5epss 0.30
Microsoft Office Security Feature Bypass Vulnerability
- risk 0.44cvss 6.8epss 0.01
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.44cvss 6.7epss 0.01
Microsoft Outlook Remote Code Execution Vulnerability
- risk 0.44cvss 6.7epss 0.01
Microsoft Outlook Remote Code Execution Vulnerability
- risk 0.44cvss 6.5epss 0.18
Microsoft Outlook Information Disclosure Vulnerability
- risk 0.44cvss 6.8epss 0.01
Microsoft Outlook Remote Code Execution Vulnerability
- risk 0.44cvss 6.8epss 0.02
Microsoft Office Online Spoofing Vulnerability
- risk 0.44cvss 6.5epss 0.23
The GDI component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office for Mac 2011, and Office 2016 for Mac allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI Information Disclosure…
- risk 0.44cvss 6.5epss 0.22
Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information…
- risk 0.43cvss 6.5epss 0.03
Microsoft Outlook Spoofing Vulnerability
- risk 0.43cvss 6.5epss 0.04
Microsoft Outlook Information Disclosure Vulnerability
Page 36 of 66