📦 Word

by Microsoft

🔍 What is Word?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-33150

CRITICAL CVSS 9.6 Jul 11, 2023

This vulnerability allows attackers to bypass Microsoft Office security features, potentially enabling malicious code execution without user interaction. It affects Microsoft Office applications on Wi...

CVE-2026-21511

HIGH CVSS 7.5 Feb 10, 2026

This vulnerability allows attackers to spoof identities or data in Microsoft Office Outlook by exploiting insecure deserialization of untrusted data. Organizations using affected Outlook versions are ...

CVE-2026-20948

HIGH CVSS 7.8 Jan 13, 2026

This vulnerability allows an unauthorized attacker to execute arbitrary code on a local system by exploiting an untrusted pointer dereference in Microsoft Office Word. Attackers can achieve this by tr...

CVE-2025-53733

HIGH CVSS 8.4 Aug 12, 2025

A type conversion vulnerability in Microsoft Office Word allows attackers to execute arbitrary code on vulnerable systems by tricking users into opening malicious documents. This affects all users run...

CVE-2025-49698

HIGH CVSS 7.8 Jul 8, 2025

This vulnerability is a use-after-free flaw in Microsoft Office Word that allows an attacker to execute arbitrary code on a victim's system by tricking them into opening a malicious document. It affec...

CVE-2025-49700

HIGH CVSS 7.8 Jul 8, 2025

A use-after-free vulnerability in Microsoft Office Word allows attackers to execute arbitrary code on affected systems by tricking users into opening malicious documents. This affects users running vu...

CVE-2025-47168

HIGH CVSS 7.8 Jun 10, 2025

A use-after-free vulnerability in Microsoft Office Word allows attackers to execute arbitrary code on a victim's system by tricking them into opening a malicious document. This affects users running v...

CVE-2025-29816

HIGH CVSS 7.5 Apr 8, 2025

This vulnerability allows attackers to bypass security features in Microsoft Word through improper input validation. Attackers can exploit this over a network to potentially execute malicious code or ...

CVE-2025-27747

HIGH CVSS 7.8 Apr 8, 2025

A use-after-free vulnerability in Microsoft Office Word allows attackers to execute arbitrary code on affected systems by tricking users into opening malicious documents. This affects all users runnin...

CVE-2025-24079

HIGH CVSS 7.8 Mar 11, 2025

A use-after-free vulnerability in Microsoft Office Word allows attackers to execute arbitrary code on vulnerable systems by tricking users into opening malicious documents. This affects all users runn...

CVE-2025-24078

HIGH CVSS 7.0 Mar 11, 2025

A use-after-free vulnerability in Microsoft Office Word allows attackers to execute arbitrary code on affected systems by tricking users into opening malicious documents. This affects users running vu...

CVE-2024-41165

HIGH CVSS 7.1 Dec 18, 2024

A library injection vulnerability in Microsoft Word 16.83 for macOS allows malicious applications to inject specially crafted libraries, leveraging Word's access privileges to bypass permissions. This...

CVE-2024-49033

HIGH CVSS 7.5 Nov 12, 2024

This vulnerability allows attackers to bypass security features in Microsoft Word, potentially enabling them to execute malicious code or access restricted content. It affects users running vulnerable...

CVE-2023-36762

HIGH CVSS 7.3 Sep 12, 2023

CVE-2023-36762 is a remote code execution vulnerability in Microsoft Word that allows attackers to execute arbitrary code on a victim's system by tricking them into opening a specially crafted malicio...

CVE-2023-29335

HIGH CVSS 7.5 May 9, 2023

CVE-2023-29335 is a security feature bypass vulnerability in Microsoft Word that allows attackers to circumvent security protections and potentially execute malicious code. This affects users of Micro...

CVE-2022-26903

HIGH CVSS 7.8 Apr 15, 2022

CVE-2022-26903 is a remote code execution vulnerability in the Windows Graphics Component that allows attackers to execute arbitrary code on affected systems. This vulnerability affects Windows operat...

CVE-2022-21842

HIGH CVSS 7.8 Jan 11, 2022

CVE-2022-21842 is a remote code execution vulnerability in Microsoft Word that allows attackers to execute arbitrary code by tricking users into opening specially crafted documents. This affects users...

CVE-2021-34452

HIGH CVSS 7.8 Jul 16, 2021

This vulnerability allows remote code execution through specially crafted Microsoft Word documents. Attackers can exploit this by tricking users into opening malicious files, potentially gaining contr...

CVE-2021-31177

HIGH CVSS 7.8 May 11, 2021

CVE-2021-31177 is a use-after-free vulnerability in Microsoft Office that allows remote code execution when a user opens a specially crafted Office document. Attackers can exploit this to execute arbi...

CVE-2021-28453

HIGH CVSS 7.8 Apr 13, 2021

CVE-2021-28453 is a remote code execution vulnerability in Microsoft Word that allows attackers to execute arbitrary code by tricking users into opening specially crafted documents. This affects users...

CVE-2020-16933

HIGH CVSS 7.0 Oct 16, 2020

CVE-2020-16933 is a security feature bypass vulnerability in Microsoft Word that allows specially crafted .LNK files to execute actions with the current user's permissions. Attackers can exploit this ...

CVE-2020-1583

HIGH CVSS 8.8 Aug 17, 2020

This is a memory disclosure vulnerability in Microsoft Word where specially crafted documents can leak memory contents when opened. Attackers could use leaked information to further compromise systems...

CVE-2019-1201

HIGH CVSS 7.8 Aug 14, 2019

A remote code execution vulnerability in Microsoft Word allows attackers to execute arbitrary code by tricking users into opening malicious files. The vulnerability affects users of Microsoft Word sof...

CVE-2024-49065

MEDIUM CVSS 5.5 Dec 12, 2024

This vulnerability in Microsoft Office allows attackers to execute arbitrary code on a victim's system by tricking them into opening a specially crafted document. It affects users of Microsoft Office ...