« Volver al listado

Microsoft

Microsoft Office: vulnerabilidades y CVE

Microsoft Office tiene 1028 vulnerabilidades publicadas, 82 de ellas en los últimos 12 meses. 13 son críticas y 35 figuran en el catálogo de explotación activa de CISA.

CVE1028
Últimos 12 meses82
Críticas13
Explotadas activamente35

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2009-0238Alta (8.8)43%⚠ Explotación activa25 feb 2009
Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office…
CVE-2012-1854Alta (7.8)21%⚠ Explotación activa10 jul 2012
Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications…
CVE-2026-21509Alta (7.8)71%⚠ Explotación activa26 ene 2026
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
CVE-2007-0671Alta (8.8)43%⚠ Explotación activa3 feb 2007
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as…
CVE-2023-36761Media (6.5)20%⚠ Explotación activa12 sept 2023
Microsoft Word Information Disclosure Vulnerability
CVE-2023-35311Alta (7.5)16%⚠ Explotación activa11 jul 2023
Microsoft Outlook Security Feature Bypass Vulnerability
CVE-2023-23397Crítica (9.8)97%⚠ Explotación activa14 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
CVE-2009-0563Alta (7.8)63%⚠ Explotación activa10 jun 2009
Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3;…
CVE-2009-0557Alta (7.8)53%⚠ Explotación activa10 jun 2009
Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel…
CVE-2006-2492Alta (8.8)48%⚠ Explotación activa20 may 2006
Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object…
CVE-2013-1331Alta (7.8)80%⚠ Explotación activa12 jun 2013
Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office…
CVE-2021-38646Alta (7.8)8.0%⚠ Explotación activa15 sept 2021
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
CVE-2015-1770Alta (8.8)35%⚠ Explotación activa10 jun 2015
Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Uninitialized Memory Use Vulnerability."
CVE-2019-1297Alta (8.8)22%⚠ Explotación activa11 sept 2019
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
CVE-2009-3129Alta (7.8)84%⚠ Explotación activa11 nov 2009
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office…
CVE-2010-3333Alta (7.8)89%⚠ Explotación activa10 nov 2010
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote…
CVE-2012-1856Alta (8.8)72%⚠ Explotación activa15 ago 2012
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL…
CVE-2015-2424Alta (8.8)40%⚠ Explotación activa14 jul 2015
Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of…
CVE-2015-1642Alta (7.8)53%⚠ Explotación activa15 ago 2015
Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
CVE-2015-2545Alta (7.8)86%⚠ Explotación activa9 sept 2015
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka "Microsoft Office Malformed EPS File Vulnerability."

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-40058Alta (8.8)0.08%—15 sept 2026
CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled…
CVE-2026-70105Alta (7.5)0.97%—20 ago 2026
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
CVE-2026-55054Media (6.5)0.92%—14 jul 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2026-47293Alta (7)0.26%—9 jun 2026
Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
CVE-2026-42832Media (5.5)0.31%—12 may 2026
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
CVE-2026-42831Alta (7.8)0.47%—12 may 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40421Media (4.3)0.70%—12 may 2026
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-40420Alta (8.8)0.30%—12 may 2026
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-40419Alta (7.8)0.33%—12 may 2026
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-40418Alta (7.8)0.33%—12 may 2026
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-40367Alta (8.4)0.45%—12 may 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40366Alta (8.4)0.36%—12 may 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40364Alta (8.4)0.36%—12 may 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40363Alta (8.4)0.36%—12 may 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40362Alta (7.8)0.47%—12 may 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-40361Alta (8.4)0.36%—12 may 2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40360Alta (7.8)0.47%—12 may 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-40359Alta (7.8)0.47%—12 may 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-40358Alta (8.4)0.36%—12 may 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-35440Media (5.5)0.55%—12 may 2026
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-35436Alta (8.8)0.30%—12 may 2026
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-32200Alta (7.8)0.47%—14 abr 2026
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2026-32199Alta (7.8)0.47%—14 abr 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-32198Alta (7.8)0.47%—14 abr 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-32197Alta (7.8)0.47%—14 abr 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-32190Alta (8.4)0.36%—14 abr 2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-32189Alta (7.8)0.47%—14 abr 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-32188Alta (7.1)0.53%—14 abr 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-26113Alta (7.8)0.41%—10 mar 2026
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-26112Alta (7.8)0.47%—10 mar 2026
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1204.002 Malicious File3
  2. T1499.004 Application or System Exploitation3
  3. T1574 Hijack Execution Flow3
  4. T1566 Phishing2
  5. T1005 Data from Local System1
  6. T1068 Exploitation for Privilege Escalation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft