« Volver al listado

Microsoft

Microsoft Office 2019: vulnerabilidades y CVE

Microsoft Office 2019 tiene 292 vulnerabilidades publicadas, 287 de ellas en los últimos 12 meses. 2 son críticas y 5 figuran en el catálogo de explotación activa de CISA.

CVE292
Últimos 12 meses287
Críticas2
Explotadas activamente5

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2024-21413Crítica (9.8)95%⚠ Explotación activa13 feb 2024
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2024-38226Alta (7.3)2.7%⚠ Explotación activa10 sept 2024
Microsoft Publisher Security Feature Bypass Vulnerability
CVE-2024-38189Alta (8.8)8.2%⚠ Explotación activa13 ago 2024
Microsoft Project Remote Code Execution Vulnerability
CVE-2021-38646Alta (7.8)8.0%⚠ Explotación activa15 sept 2021
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
CVE-2021-42292Alta (7.8)43%⚠ Explotación activa10 nov 2021
Microsoft Excel Security Feature Bypass Vulnerability

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-85875Media (5.5)0.54%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-83951Media (5.5)0.54%—8 sept 2026
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-83949Media (5.5)0.54%—8 sept 2026
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-81960Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81959Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81958Media (5.5)0.54%—8 sept 2026
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81957Alta (7.8)0.47%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81956Alta (7.8)0.47%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81954Alta (7.8)0.47%—8 sept 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81953Alta (7.8)0.47%—8 sept 2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81952Alta (8.8)0.82%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-81951Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81950Alta (7.8)0.47%—8 sept 2026
Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81949Alta (7.8)0.47%—8 sept 2026
Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81948Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81947Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81401Media (5.5)0.54%—8 sept 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81400Media (5.5)0.54%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81399Media (5.5)0.54%—8 sept 2026
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81398Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81397Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81396Alta (7.8)0.47%—8 sept 2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81395Media (5.5)0.54%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81394Media (5.5)0.55%—8 sept 2026
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81393Media (5.5)0.54%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81392Media (5.5)0.54%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81391Media (5.5)0.54%—8 sept 2026
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81390Media (5.5)0.54%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81389Alta (7)0.37%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81388Alta (7.8)0.47%—8 sept 2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter3
  2. T1068 Exploitation for Privilege Escalation2
  3. T1203 Exploitation for Client Execution2
  4. T1059.003 Windows Command Shell1
  5. T1059.005 Visual Basic1
  6. T1190 Exploit Public-Facing Application1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft