📦 Office

by Microsoft

🔍 What is Office?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-60724

CRITICAL CVSS 9.8 Nov 11, 2025

A heap-based buffer overflow vulnerability in Microsoft Graphics Component allows remote attackers to execute arbitrary code on vulnerable systems. This affects systems running Microsoft Windows with ...

CVE-2025-53766

CRITICAL CVSS 9.8 Aug 12, 2025

A heap-based buffer overflow vulnerability in Windows GDI+ allows remote attackers to execute arbitrary code on affected systems. This vulnerability affects Windows systems with GDI+ components and ca...

CVE-2023-33150

CRITICAL CVSS 9.6 Jul 11, 2023

This vulnerability allows attackers to bypass Microsoft Office security features, potentially enabling malicious code execution without user interaction. It affects Microsoft Office applications on Wi...

CVE-2023-23397

CRITICAL CVSS 9.8 Mar 14, 2023

CVE-2023-23397 is a critical elevation of privilege vulnerability in Microsoft Outlook that allows attackers to steal NTLM hashes without user interaction. When exploited, it enables credential theft ...

CVE-2019-1205

CRITICAL CVSS 9.8 Aug 14, 2019

A remote code execution vulnerability in Microsoft Word allows attackers to execute arbitrary code by tricking users into opening malicious files. This affects users of Microsoft Word who open special...

CVE-2026-21511

HIGH CVSS 7.5 Feb 10, 2026

This vulnerability allows attackers to spoof identities or data in Microsoft Office Outlook by exploiting insecure deserialization of untrusted data. Organizations using affected Outlook versions are ...

CVE-2026-21259

HIGH CVSS 7.8 Feb 10, 2026

A heap-based buffer overflow vulnerability in Microsoft Office Excel allows local attackers to execute arbitrary code with elevated privileges. This affects users who open malicious Excel files. The v...

CVE-2026-21509

HIGH CVSS 7.8 Jan 26, 2026

This vulnerability in Microsoft Office allows an attacker to bypass local security features by manipulating untrusted inputs. It affects users running vulnerable versions of Microsoft Office applicati...

CVE-2026-20953

HIGH CVSS 8.4 Jan 13, 2026

This CVE describes a use-after-free vulnerability in Microsoft Office that allows an unauthorized attacker to execute arbitrary code on a victim's system. Attackers can exploit this by tricking users ...

CVE-2026-20955

HIGH CVSS 7.8 Jan 13, 2026

This vulnerability allows an attacker to execute arbitrary code on a victim's system by exploiting an untrusted pointer dereference in Microsoft Excel. Attackers can achieve this by tricking users int...

CVE-2026-20957

HIGH CVSS 7.8 Jan 13, 2026

An integer underflow vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on affected systems by opening specially crafted Excel files. This affects users running vulnera...

CVE-2026-20946

HIGH CVSS 7.8 Jan 13, 2026

This vulnerability allows an attacker to execute arbitrary code on a victim's system by exploiting an out-of-bounds read in Microsoft Excel. Users who open malicious Excel files are affected, potentia...

CVE-2026-20948

HIGH CVSS 7.8 Jan 13, 2026

This vulnerability allows an unauthorized attacker to execute arbitrary code on a local system by exploiting an untrusted pointer dereference in Microsoft Office Word. Attackers can achieve this by tr...

CVE-2026-20950

HIGH CVSS 7.8 Jan 13, 2026

This vulnerability is a use-after-free memory corruption flaw in Microsoft Office Excel that allows an attacker to execute arbitrary code on a victim's system by tricking them into opening a malicious...

CVE-2026-20952

HIGH CVSS 8.4 Jan 13, 2026

This CVE describes a use-after-free vulnerability in Microsoft Office that allows an unauthorized attacker to execute arbitrary code on a victim's system. Attackers can exploit this by tricking users ...

CVE-2026-20943

HIGH CVSS 7.0 Jan 13, 2026

This vulnerability allows an unauthorized attacker to execute arbitrary code on a local system by exploiting an untrusted search path in Microsoft Office. Attackers can place malicious DLLs in directo...

CVE-2025-62199

HIGH CVSS 7.8 Nov 11, 2025

CVE-2025-62199 is a use-after-free vulnerability in Microsoft Office that allows an attacker to execute arbitrary code on a victim's system by tricking them into opening a malicious Office document. T...

CVE-2025-62200

HIGH CVSS 7.8 Nov 11, 2025

This vulnerability allows an attacker to execute arbitrary code on a victim's system by exploiting an untrusted pointer dereference in Microsoft Excel. Attackers can achieve this by tricking users int...

CVE-2025-62201

HIGH CVSS 7.8 Nov 11, 2025

A heap-based buffer overflow vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on a victim's system by tricking them into opening a malicious Excel file. This affects ...

CVE-2025-62202

HIGH CVSS 7.1 Nov 11, 2025

An out-of-bounds read vulnerability in Microsoft Office Excel allows an attacker to read memory contents beyond intended boundaries, potentially exposing sensitive information. This affects users who ...

CVE-2025-62203

HIGH CVSS 7.8 Nov 11, 2025

This vulnerability is a use-after-free flaw in Microsoft Office Excel that allows an unauthorized attacker to execute arbitrary code on a victim's system by tricking them into opening a malicious Exce...

CVE-2025-60726

HIGH CVSS 7.1 Nov 11, 2025

This vulnerability is an out-of-bounds read flaw in Microsoft Excel that allows an attacker to read memory contents they shouldn't have access to. Attackers could exploit this by tricking users into o...

CVE-2025-60727

HIGH CVSS 7.8 Nov 11, 2025

This vulnerability allows an attacker to read memory outside the intended buffer in Microsoft Excel, potentially leading to information disclosure or remote code execution. Users who open malicious Ex...

CVE-2025-54906

HIGH CVSS 7.8 Sep 9, 2025

This vulnerability in Microsoft Office involves a use-after-free memory corruption issue that allows an attacker to execute arbitrary code on a victim's system. Attackers can exploit this by tricking ...

CVE-2025-54908

HIGH CVSS 7.8 Sep 9, 2025

This vulnerability is a use-after-free memory corruption flaw in Microsoft Office PowerPoint that allows an unauthorized attacker to execute arbitrary code on a victim's system. Attackers can exploit ...

CVE-2025-54900

HIGH CVSS 7.8 Sep 9, 2025

A heap-based buffer overflow vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on affected systems by tricking users into opening malicious Excel files. This affects a...

CVE-2025-54902

HIGH CVSS 7.8 Sep 9, 2025

An out-of-bounds read vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on affected systems by tricking users into opening malicious Excel files. This affects users ru...

CVE-2025-54904

HIGH CVSS 7.8 Sep 9, 2025

This vulnerability is a use-after-free memory corruption flaw in Microsoft Office Excel that allows an attacker to execute arbitrary code on a victim's system by tricking them into opening a malicious...

CVE-2025-54896

HIGH CVSS 7.8 Sep 9, 2025

This vulnerability is a use-after-free memory corruption flaw in Microsoft Office Excel that allows an unauthorized attacker to execute arbitrary code on a victim's system. Attackers can exploit this ...

CVE-2025-54898

HIGH CVSS 7.8 Sep 9, 2025

This vulnerability allows an attacker to execute arbitrary code on a victim's system by exploiting an out-of-bounds read in Microsoft Excel. Attackers can achieve this by tricking users into opening a...

CVE-2025-53739

HIGH CVSS 7.8 Aug 12, 2025

A type confusion vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on a victim's system by tricking them into opening a malicious Excel file. This affects all users ru...

CVE-2025-53741

HIGH CVSS 7.8 Aug 12, 2025

A heap-based buffer overflow vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on affected systems by tricking users into opening malicious Excel files. This affects a...

CVE-2025-53733

HIGH CVSS 8.4 Aug 12, 2025

A type conversion vulnerability in Microsoft Office Word allows attackers to execute arbitrary code on vulnerable systems by tricking users into opening malicious documents. This affects all users run...

CVE-2025-53735

HIGH CVSS 7.8 Aug 12, 2025

This vulnerability is a use-after-free memory corruption flaw in Microsoft Office Excel that allows an attacker to execute arbitrary code on a victim's system by tricking them into opening a malicious...

CVE-2025-53737

HIGH CVSS 7.8 Aug 12, 2025

A heap-based buffer overflow vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on vulnerable systems by tricking users into opening malicious Excel files. This affects...

CVE-2025-53731

HIGH CVSS 8.4 Aug 12, 2025

A use-after-free vulnerability in Microsoft Office allows attackers to execute arbitrary code on a victim's system by tricking them into opening a malicious document. This affects all users running vu...

CVE-2025-49711

HIGH CVSS 7.8 Jul 8, 2025

A use-after-free vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on a victim's system by tricking them into opening a malicious Excel file. This affects all users ru...

CVE-2025-49702

HIGH CVSS 7.8 Jul 8, 2025

A type confusion vulnerability in Microsoft Office allows attackers to execute arbitrary code on vulnerable systems by tricking users into opening malicious documents. This affects users running unpat...

CVE-2025-49698

HIGH CVSS 7.8 Jul 8, 2025

This vulnerability is a use-after-free flaw in Microsoft Office Word that allows an attacker to execute arbitrary code on a victim's system by tricking them into opening a malicious document. It affec...

CVE-2025-49700

HIGH CVSS 7.8 Jul 8, 2025

A use-after-free vulnerability in Microsoft Office Word allows attackers to execute arbitrary code on affected systems by tricking users into opening malicious documents. This affects users running vu...

CVE-2025-49696

HIGH CVSS 8.4 Jul 8, 2025

This vulnerability allows an attacker to read memory outside the intended buffer in Microsoft Office applications, potentially leading to local code execution. Users who open malicious Office document...

CVE-2025-47168

HIGH CVSS 7.8 Jun 10, 2025

A use-after-free vulnerability in Microsoft Office Word allows attackers to execute arbitrary code on a victim's system by tricking them into opening a malicious document. This affects users running v...

CVE-2025-47164

HIGH CVSS 8.4 Jun 10, 2025

A use-after-free vulnerability in Microsoft Office allows attackers to execute arbitrary code on affected systems by tricking users into opening malicious documents. This affects all users running vul...

CVE-2025-47162

HIGH CVSS 8.4 Jun 10, 2025

A heap-based buffer overflow vulnerability in Microsoft Office allows attackers to execute arbitrary code on affected systems by tricking users into opening malicious documents. This affects all users...

CVE-2025-32704

HIGH CVSS 8.4 May 13, 2025

A buffer over-read vulnerability in Microsoft Office Excel allows attackers to read beyond allocated memory boundaries, potentially leading to information disclosure or remote code execution. This aff...

CVE-2026-21261

MEDIUM CVSS 5.5 Feb 10, 2026

This vulnerability allows an unauthorized attacker to read memory outside the intended buffer in Microsoft Excel, potentially exposing sensitive information. It affects users who open malicious Excel ...

CVE-2026-21258

MEDIUM CVSS 5.5 Feb 10, 2026

This vulnerability in Microsoft Office Excel allows an attacker to exploit improper input validation to access sensitive information from the local system. Users who open malicious Excel files are aff...

CVE-2025-59240

MEDIUM CVSS 5.5 Nov 11, 2025

This vulnerability in Microsoft Office Excel allows an unauthorized local attacker to access sensitive information from Excel files. It affects users running vulnerable versions of Excel who open mali...

CVE-2025-53799

MEDIUM CVSS 5.5 Sep 9, 2025

CVE-2025-53799 is an information disclosure vulnerability in Windows Imaging Component where uninitialized memory resources can be accessed by a local attacker. This allows reading of potentially sens...

CVE-2025-48812

MEDIUM CVSS 5.5 Jul 8, 2025

This vulnerability allows an attacker to read memory outside the intended buffer in Microsoft Excel, potentially exposing sensitive information from the application's memory. It affects users who open...

CVE-2025-21357

MEDIUM CVSS 6.7 Jan 14, 2025

Microsoft Outlook contains a remote code execution vulnerability that allows attackers to execute arbitrary code on a victim's system by sending a specially crafted email. This affects users running v...

CVE-2024-49065

MEDIUM CVSS 5.5 Dec 12, 2024

This vulnerability in Microsoft Office allows attackers to execute arbitrary code on a victim's system by tricking them into opening a specially crafted document. It affects users of Microsoft Office ...

CVE-2024-43609

MEDIUM CVSS 6.5 Oct 8, 2024

This Microsoft Office spoofing vulnerability allows attackers to craft malicious documents that appear legitimate to users. It affects users who open untrusted Office documents, potentially leading to...

CVE-2020-1224

MEDIUM CVSS 5.5 Sep 11, 2020

This is a memory information disclosure vulnerability in Microsoft Excel where specially crafted documents can leak memory contents. Attackers could use leaked information to compromise systems or dat...

CVE-2020-16855

MEDIUM CVSS 5.5 Sep 11, 2020

This CVE describes an information disclosure vulnerability in Microsoft Office where uninitialized memory could be read when opening specially crafted files. Attackers could exploit this to view out-o...

CVE-2020-1493

MEDIUM CVSS 5.5 Aug 17, 2020

This CVE describes an information disclosure vulnerability in Microsoft Outlook where files attached as links to emails could be accessed by unauthorized users. Attackers could share email attachments...

CVE-2020-1502

MEDIUM CVSS 5.5 Aug 17, 2020

This is an information disclosure vulnerability in Microsoft Word where specially crafted documents can leak memory contents when opened. Attackers could potentially use leaked information to further ...

CVE-2020-1483

MEDIUM CVSS 5.0 Aug 17, 2020

This is a remote code execution vulnerability in Microsoft Outlook where specially crafted files can trigger memory handling errors, allowing attackers to run arbitrary code as the current user. Users...

CVE-2019-1153

MEDIUM CVSS 5.5 Aug 14, 2019

This CVE-2019-1153 is an information disclosure vulnerability in Microsoft Windows Graphics Component that allows an attacker to read memory contents they shouldn't access. It affects Windows systems ...

CVE-2019-1148

MEDIUM CVSS 5.5 Aug 14, 2019

CVE-2019-1148 is an information disclosure vulnerability in Microsoft Windows Graphics Component that allows authenticated attackers to read memory contents they shouldn't access. This affects Windows...