Microsoft
Microsoft Office: vulnerabilidades y CVE
Microsoft Office tiene 1028 vulnerabilidades publicadas, 82 de ellas en los últimos 12 meses. 13 son críticas y 35 figuran en el catálogo de explotación activa de CISA.
CVE1028
Últimos 12 meses82
Críticas13
Explotadas activamente35
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2009-0238 | Alta (8.8) | 43% | ⚠ Explotación activa | 25 feb 2009 | Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office… |
| CVE-2012-1854 | Alta (7.8) | 21% | ⚠ Explotación activa | 10 jul 2012 | Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications… |
| CVE-2026-21509 | Alta (7.8) | 71% | ⚠ Explotación activa | 26 ene 2026 | Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally. |
| CVE-2007-0671 | Alta (8.8) | 43% | ⚠ Explotación activa | 3 feb 2007 | Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as… |
| CVE-2023-36761 | Media (6.5) | 20% | ⚠ Explotación activa | 12 sept 2023 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2023-35311 | Alta (7.5) | 16% | ⚠ Explotación activa | 11 jul 2023 | Microsoft Outlook Security Feature Bypass Vulnerability |
| CVE-2023-23397 | Crítica (9.8) | 97% | ⚠ Explotación activa | 14 mar 2023 | Microsoft Outlook Elevation of Privilege Vulnerability |
| CVE-2009-0563 | Alta (7.8) | 63% | ⚠ Explotación activa | 10 jun 2009 | Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3;… |
| CVE-2009-0557 | Alta (7.8) | 53% | ⚠ Explotación activa | 10 jun 2009 | Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel… |
| CVE-2006-2492 | Alta (8.8) | 48% | ⚠ Explotación activa | 20 may 2006 | Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object… |
| CVE-2013-1331 | Alta (7.8) | 80% | ⚠ Explotación activa | 12 jun 2013 | Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office… |
| CVE-2021-38646 | Alta (7.8) | 8.0% | ⚠ Explotación activa | 15 sept 2021 | Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability |
| CVE-2015-1770 | Alta (8.8) | 35% | ⚠ Explotación activa | 10 jun 2015 | Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Uninitialized Memory Use Vulnerability." |
| CVE-2019-1297 | Alta (8.8) | 22% | ⚠ Explotación activa | 11 sept 2019 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. |
| CVE-2009-3129 | Alta (7.8) | 84% | ⚠ Explotación activa | 11 nov 2009 | Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office… |
| CVE-2010-3333 | Alta (7.8) | 89% | ⚠ Explotación activa | 10 nov 2010 | Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote… |
| CVE-2012-1856 | Alta (8.8) | 72% | ⚠ Explotación activa | 15 ago 2012 | The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL… |
| CVE-2015-2424 | Alta (8.8) | 40% | ⚠ Explotación activa | 14 jul 2015 | Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of… |
| CVE-2015-1642 | Alta (7.8) | 53% | ⚠ Explotación activa | 15 ago 2015 | Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." |
| CVE-2015-2545 | Alta (7.8) | 86% | ⚠ Explotación activa | 9 sept 2015 | Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka "Microsoft Office Malformed EPS File Vulnerability." |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-40058 | Alta (8.8) | 0.08% | — | 15 sept 2026 | CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled… |
| CVE-2026-70105 | Alta (7.5) | 0.97% | — | 20 ago 2026 | Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-55054 | Media (6.5) | 0.92% | — | 14 jul 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-47293 | Alta (7) | 0.26% | — | 9 jun 2026 | Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. |
| CVE-2026-42832 | Media (5.5) | 0.31% | — | 12 may 2026 | Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. |
| CVE-2026-42831 | Alta (7.8) | 0.47% | — | 12 may 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-40421 | Media (4.3) | 0.70% | — | 12 may 2026 | Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
| CVE-2026-40420 | Alta (8.8) | 0.30% | — | 12 may 2026 | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. |
| CVE-2026-40419 | Alta (7.8) | 0.33% | — | 12 may 2026 | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. |
| CVE-2026-40418 | Alta (7.8) | 0.33% | — | 12 may 2026 | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. |
| CVE-2026-40367 | Alta (8.4) | 0.45% | — | 12 may 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-40366 | Alta (8.4) | 0.36% | — | 12 may 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-40364 | Alta (8.4) | 0.36% | — | 12 may 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-40363 | Alta (8.4) | 0.36% | — | 12 may 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-40362 | Alta (7.8) | 0.47% | — | 12 may 2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-40361 | Alta (8.4) | 0.36% | — | 12 may 2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-40360 | Alta (7.8) | 0.47% | — | 12 may 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-40359 | Alta (7.8) | 0.47% | — | 12 may 2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-40358 | Alta (8.4) | 0.36% | — | 12 may 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-35440 | Media (5.5) | 0.55% | — | 12 may 2026 | Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
| CVE-2026-35436 | Alta (8.8) | 0.30% | — | 12 may 2026 | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. |
| CVE-2026-32200 | Alta (7.8) | 0.47% | — | 14 abr 2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
| CVE-2026-32199 | Alta (7.8) | 0.47% | — | 14 abr 2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-32198 | Alta (7.8) | 0.47% | — | 14 abr 2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-32197 | Alta (7.8) | 0.47% | — | 14 abr 2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-32190 | Alta (8.4) | 0.36% | — | 14 abr 2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-32189 | Alta (7.8) | 0.47% | — | 14 abr 2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-32188 | Alta (7.1) | 0.53% | — | 14 abr 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-26113 | Alta (7.8) | 0.41% | — | 10 mar 2026 | Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-26112 | Alta (7.8) | 0.47% | — | 10 mar 2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.