Office For Mac
by Microsoft
CVEs (261)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-24473 | Hig | 0.51 | 7.8 | 0.02 | Apr 15, 2022 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2022-22003 | Hig | 0.51 | 7.8 | 0.02 | Feb 9, 2022 | Microsoft Office Graphics Remote Code Execution Vulnerability | ||
| CVE-2022-21841 | Hig | 0.51 | 7.8 | 0.03 | Jan 11, 2022 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2018-8412 | Hig | 0.51 | 7.8 | 0.01 | Aug 15, 2018 | An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing them, aka "Microsoft (MAU) Office Elevation of Privilege Vulnerability." This affects Microsoft Office. | ||
| CVE-2026-21511 | Hig | 0.49 | 7.5 | 0.04 | Feb 10, 2026 | Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-29816 | Hig | 0.49 | 7.5 | 0.00 | Apr 8, 2025 | Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2025-26687 | Hig | 0.49 | 7.5 | 0.01 | Apr 8, 2025 | Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2024-49033 | Hig | 0.49 | 7.5 | 0.02 | Nov 12, 2024 | Microsoft Word Security Feature Bypass Vulnerability | ||
| CVE-2022-44713 | Hig | 0.49 | 7.5 | 0.01 | Dec 13, 2022 | Microsoft Outlook for Mac Spoofing Vulnerability | ||
| CVE-2023-36762 | Hig | 0.48 | 7.3 | 0.01 | Sep 12, 2023 | Microsoft Word Remote Code Execution Vulnerability | ||
| CVE-2016-7276 | Hig | 0.48 | 7.1 | 0.25 | Dec 20, 2016 | Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office for Mac 2011, and Office 2016 for Mac allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office… | ||
| CVE-2025-62555 | Hig | 0.46 | 7.0 | 0.01 | Dec 9, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-62202 | Hig | 0.46 | 7.1 | 0.01 | Nov 11, 2025 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2025-60726 | Hig | 0.46 | 7.1 | 0.01 | Nov 11, 2025 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2025-59235 | Hig | 0.46 | 7.1 | 0.01 | Oct 14, 2025 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2025-59232 | Hig | 0.46 | 7.1 | 0.00 | Oct 14, 2025 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2025-59221 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-54905 | Hig | 0.46 | 7.1 | 0.01 | Sep 9, 2025 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2025-49699 | Hig | 0.46 | 7.0 | 0.00 | Jul 8, 2025 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-24078 | Hig | 0.46 | 7.0 | 0.01 | Mar 11, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
- risk 0.51cvss 7.8epss 0.02
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.02
Microsoft Office Graphics Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.03
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing them, aka "Microsoft (MAU) Office Elevation of Privilege Vulnerability." This affects Microsoft Office.
- risk 0.49cvss 7.5epss 0.04
Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
- risk 0.49cvss 7.5epss 0.00
Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.49cvss 7.5epss 0.01
Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network.
- risk 0.49cvss 7.5epss 0.02
Microsoft Word Security Feature Bypass Vulnerability
- risk 0.49cvss 7.5epss 0.01
Microsoft Outlook for Mac Spoofing Vulnerability
- risk 0.48cvss 7.3epss 0.01
Microsoft Word Remote Code Execution Vulnerability
- risk 0.48cvss 7.1epss 0.25
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office for Mac 2011, and Office 2016 for Mac allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office…
- risk 0.46cvss 7.0epss 0.01
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.1epss 0.01
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.46cvss 7.1epss 0.01
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.46cvss 7.1epss 0.01
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.46cvss 7.1epss 0.00
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.1epss 0.01
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.0epss 0.01
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Page 10 of 14