« Volver al listado

Microsoft

Microsoft Excel: vulnerabilidades y CVE

Microsoft Excel tiene 505 vulnerabilidades publicadas, 141 de ellas en los últimos 12 meses. 2 son críticas y 6 figuran en el catálogo de explotación activa de CISA.

CVE505
Últimos 12 meses141
Críticas2
Explotadas activamente6

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2009-0238Alta (8.8)43%⚠ Explotación activa25 feb 2009
Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office…
CVE-2007-0671Alta (8.8)43%⚠ Explotación activa3 feb 2007
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as…
CVE-2019-1297Alta (8.8)22%⚠ Explotación activa11 sept 2019
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
CVE-2009-3129Alta (7.8)84%⚠ Explotación activa11 nov 2009
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office…
CVE-2016-7262Alta (7.8)58%⚠ Explotación activa20 dic 2016
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted…
CVE-2021-42292Alta (7.8)43%⚠ Explotación activa10 nov 2021
Microsoft Excel Security Feature Bypass Vulnerability

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-85875Media (5.5)0.54%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81960Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81959Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81958Media (5.5)0.54%—8 sept 2026
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81957Alta (7.8)0.47%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81956Alta (7.8)0.47%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81954Alta (7.8)0.47%—8 sept 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81953Alta (7.8)0.47%—8 sept 2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81951Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81950Alta (7.8)0.47%—8 sept 2026
Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81949Alta (7.8)0.47%—8 sept 2026
Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81948Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81947Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81401Media (5.5)0.54%—8 sept 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81400Media (5.5)0.54%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81399Media (5.5)0.54%—8 sept 2026
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81398Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81397Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81396Alta (7.8)0.47%—8 sept 2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81395Media (5.5)0.54%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81394Media (5.5)0.55%—8 sept 2026
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81393Media (5.5)0.54%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81392Media (5.5)0.54%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81391Media (5.5)0.54%—8 sept 2026
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81390Media (5.5)0.54%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81389Alta (7)0.37%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81388Alta (7.8)0.47%—8 sept 2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81387Media (5.5)0.55%—8 sept 2026
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81386Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-78518Alta (8.8)0.86%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution24
  2. T1059 Command and Scripting Interpreter23
  3. T1059.005 Visual Basic1
  4. T1204.002 Malicious File1
  5. T1499.004 Application or System Exploitation1
  6. T1566 Phishing1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft