📦 Office Online Server

by Microsoft

🔍 What is Office Online Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2019-1205

CRITICAL CVSS 9.8 Aug 14, 2019

A remote code execution vulnerability in Microsoft Word allows attackers to execute arbitrary code by tricking users into opening malicious files. This affects users of Microsoft Word who open special...

CVE-2026-21259

HIGH CVSS 7.8 Feb 10, 2026

A heap-based buffer overflow vulnerability in Microsoft Office Excel allows local attackers to execute arbitrary code with elevated privileges. This affects users who open malicious Excel files. The v...

CVE-2026-20955

HIGH CVSS 7.8 Jan 13, 2026

This vulnerability allows an attacker to execute arbitrary code on a victim's system by exploiting an untrusted pointer dereference in Microsoft Excel. Attackers can achieve this by tricking users int...

CVE-2026-20957

HIGH CVSS 7.8 Jan 13, 2026

An integer underflow vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on affected systems by opening specially crafted Excel files. This affects users running vulnera...

CVE-2026-20950

HIGH CVSS 7.8 Jan 13, 2026

This vulnerability is a use-after-free memory corruption flaw in Microsoft Office Excel that allows an attacker to execute arbitrary code on a victim's system by tricking them into opening a malicious...

CVE-2025-62200

HIGH CVSS 7.8 Nov 11, 2025

This vulnerability allows an attacker to execute arbitrary code on a victim's system by exploiting an untrusted pointer dereference in Microsoft Excel. Attackers can achieve this by tricking users int...

CVE-2025-62201

HIGH CVSS 7.8 Nov 11, 2025

A heap-based buffer overflow vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on a victim's system by tricking them into opening a malicious Excel file. This affects ...

CVE-2025-62202

HIGH CVSS 7.1 Nov 11, 2025

An out-of-bounds read vulnerability in Microsoft Office Excel allows an attacker to read memory contents beyond intended boundaries, potentially exposing sensitive information. This affects users who ...

CVE-2025-62203

HIGH CVSS 7.8 Nov 11, 2025

This vulnerability is a use-after-free flaw in Microsoft Office Excel that allows an unauthorized attacker to execute arbitrary code on a victim's system by tricking them into opening a malicious Exce...

CVE-2025-60726

HIGH CVSS 7.1 Nov 11, 2025

This vulnerability is an out-of-bounds read flaw in Microsoft Excel that allows an attacker to read memory contents they shouldn't have access to. Attackers could exploit this by tricking users into o...

CVE-2025-60727

HIGH CVSS 7.8 Nov 11, 2025

This vulnerability allows an attacker to read memory outside the intended buffer in Microsoft Excel, potentially leading to information disclosure or remote code execution. Users who open malicious Ex...

CVE-2025-54900

HIGH CVSS 7.8 Sep 9, 2025

A heap-based buffer overflow vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on affected systems by tricking users into opening malicious Excel files. This affects a...

CVE-2025-54902

HIGH CVSS 7.8 Sep 9, 2025

An out-of-bounds read vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on affected systems by tricking users into opening malicious Excel files. This affects users ru...

CVE-2025-54904

HIGH CVSS 7.8 Sep 9, 2025

This vulnerability is a use-after-free memory corruption flaw in Microsoft Office Excel that allows an attacker to execute arbitrary code on a victim's system by tricking them into opening a malicious...

CVE-2025-54896

HIGH CVSS 7.8 Sep 9, 2025

This vulnerability is a use-after-free memory corruption flaw in Microsoft Office Excel that allows an unauthorized attacker to execute arbitrary code on a victim's system. Attackers can exploit this ...

CVE-2025-54898

HIGH CVSS 7.8 Sep 9, 2025

This vulnerability allows an attacker to execute arbitrary code on a victim's system by exploiting an out-of-bounds read in Microsoft Excel. Attackers can achieve this by tricking users into opening a...

CVE-2025-53739

HIGH CVSS 7.8 Aug 12, 2025

A type confusion vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on a victim's system by tricking them into opening a malicious Excel file. This affects all users ru...

CVE-2025-53741

HIGH CVSS 7.8 Aug 12, 2025

A heap-based buffer overflow vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on affected systems by tricking users into opening malicious Excel files. This affects a...

CVE-2025-53735

HIGH CVSS 7.8 Aug 12, 2025

This vulnerability is a use-after-free memory corruption flaw in Microsoft Office Excel that allows an attacker to execute arbitrary code on a victim's system by tricking them into opening a malicious...

CVE-2025-53737

HIGH CVSS 7.8 Aug 12, 2025

A heap-based buffer overflow vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on vulnerable systems by tricking users into opening malicious Excel files. This affects...

CVE-2025-49711

HIGH CVSS 7.8 Jul 8, 2025

A use-after-free vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on a victim's system by tricking them into opening a malicious Excel file. This affects all users ru...

CVE-2025-30377

HIGH CVSS 8.4 May 13, 2025

This vulnerability is a use-after-free memory corruption flaw in Microsoft Office that allows an attacker to execute arbitrary code on a victim's system. Attackers can exploit this by tricking users i...

CVE-2025-30379

HIGH CVSS 7.8 May 13, 2025

This vulnerability in Microsoft Office Excel involves the release of an invalid pointer or reference, which could allow an attacker to execute arbitrary code on a local system. It affects users who op...

CVE-2025-29979

HIGH CVSS 7.8 May 13, 2025

A heap-based buffer overflow vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on affected systems by tricking users into opening malicious Excel files. This affects a...

CVE-2025-30375

HIGH CVSS 7.8 May 13, 2025

A type confusion vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on vulnerable systems by tricking users into opening malicious Excel files. This affects all users r...

CVE-2025-29977

HIGH CVSS 7.8 May 13, 2025

A use-after-free vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on a victim's system by tricking them into opening a malicious Excel file. This affects all users ru...

CVE-2025-27751

HIGH CVSS 7.8 Apr 8, 2025

A use-after-free vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on a victim's system by tricking them into opening a malicious Excel file. This affects all users ru...

CVE-2025-24082

HIGH CVSS 7.8 Mar 11, 2025

A use-after-free vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on affected systems by tricking users into opening malicious Excel files. This affects all users run...

CVE-2025-24081

HIGH CVSS 7.8 Mar 11, 2025

This vulnerability is a use-after-free memory corruption flaw in Microsoft Office Excel that allows an attacker to execute arbitrary code on a victim's system by tricking them into opening a malicious...

CVE-2025-24075

HIGH CVSS 7.8 Mar 11, 2025

A stack-based buffer overflow vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on vulnerable systems by tricking users into opening malicious Excel files. This affect...

CVE-2025-21394

HIGH CVSS 7.8 Feb 11, 2025

This vulnerability allows remote code execution through specially crafted Excel files. Attackers could exploit this to execute arbitrary code on a victim's system when they open a malicious Excel docu...

CVE-2025-21387

HIGH CVSS 7.8 Feb 11, 2025

This vulnerability allows remote attackers to execute arbitrary code on affected systems by tricking users into opening a specially crafted Excel file. It affects Microsoft Excel users across multiple...

CVE-2025-21381

HIGH CVSS 7.8 Feb 11, 2025

Microsoft Excel contains a remote code execution vulnerability that allows attackers to execute arbitrary code by tricking users into opening specially crafted Excel files. This affects all users runn...

CVE-2025-21362

HIGH CVSS 8.4 Jan 14, 2025

This vulnerability allows attackers to execute arbitrary code on a victim's system by tricking them into opening a specially crafted Excel file. It affects users running vulnerable versions of Microso...

CVE-2025-21354

HIGH CVSS 8.4 Jan 14, 2025

This vulnerability allows remote code execution through specially crafted Excel files. Attackers can exploit this by tricking users into opening malicious documents, potentially gaining full control o...

CVE-2024-43465

HIGH CVSS 7.8 Sep 10, 2024

This vulnerability in Microsoft Excel allows an attacker to gain elevated privileges by exploiting a use-after-free memory issue (CWE-416). Attackers could execute arbitrary code with the privileges o...

CVE-2024-30042

HIGH CVSS 7.8 May 14, 2024

This vulnerability allows remote code execution through specially crafted Excel files. Attackers can exploit this by tricking users into opening malicious documents, potentially gaining full control o...

CVE-2023-36766

HIGH CVSS 7.8 Sep 12, 2023

CVE-2023-36766 is a Microsoft Excel information disclosure vulnerability that allows an attacker to read memory contents from the Excel process. This affects users who open specially crafted Excel fil...

CVE-2023-35371

HIGH CVSS 7.8 Aug 8, 2023

This vulnerability in Microsoft Office allows attackers to execute arbitrary code on a victim's system by tricking them into opening a specially crafted Office document. It affects users of Microsoft ...

CVE-2023-33133

HIGH CVSS 7.8 Jun 14, 2023

CVE-2023-33133 is a heap-based buffer overflow vulnerability in Microsoft Excel that allows remote code execution when a user opens a specially crafted malicious Excel file. This affects users of Micr...

CVE-2023-33137

HIGH CVSS 7.8 Jun 14, 2023

This vulnerability allows attackers to execute arbitrary code on a victim's system by tricking them into opening a specially crafted Excel file. It affects users running vulnerable versions of Microso...

CVE-2026-21261

MEDIUM CVSS 5.5 Feb 10, 2026

This vulnerability allows an unauthorized attacker to read memory outside the intended buffer in Microsoft Excel, potentially exposing sensitive information. It affects users who open malicious Excel ...

CVE-2026-21258

MEDIUM CVSS 5.5 Feb 10, 2026

This vulnerability in Microsoft Office Excel allows an attacker to exploit improper input validation to access sensitive information from the local system. Users who open malicious Excel files are aff...

CVE-2025-48812

MEDIUM CVSS 5.5 Jul 8, 2025

This vulnerability allows an attacker to read memory outside the intended buffer in Microsoft Excel, potentially exposing sensitive information from the application's memory. It affects users who open...

CVE-2020-1224

MEDIUM CVSS 5.5 Sep 11, 2020

This is a memory information disclosure vulnerability in Microsoft Excel where specially crafted documents can leak memory contents. Attackers could use leaked information to compromise systems or dat...

CVE-2020-1502

MEDIUM CVSS 5.5 Aug 17, 2020

This is an information disclosure vulnerability in Microsoft Word where specially crafted documents can leak memory contents when opened. Attackers could potentially use leaked information to further ...