Microsoft
Microsoft Office Long Term Servicing Channel: vulnerabilidades y CVE
Microsoft Office Long Term Servicing Channel tiene 367 vulnerabilidades publicadas, 93 de ellas en los últimos 12 meses. 6 son críticas y 8 figuran en el catálogo de explotación activa de CISA.
CVE367
Últimos 12 meses93
Críticas6
Explotadas activamente8
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-21514 | Alta (7.8) | 1.6% | ⚠ Explotación activa | 10 feb 2026 | Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally. |
| CVE-2026-21509 | Alta (7.8) | 71% | ⚠ Explotación activa | 26 ene 2026 | Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally. |
| CVE-2024-21413 | Crítica (9.8) | 95% | ⚠ Explotación activa | 13 feb 2024 | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2024-38226 | Alta (7.3) | 2.7% | ⚠ Explotación activa | 10 sept 2024 | Microsoft Publisher Security Feature Bypass Vulnerability |
| CVE-2024-38189 | Alta (8.8) | 8.2% | ⚠ Explotación activa | 13 ago 2024 | Microsoft Project Remote Code Execution Vulnerability |
| CVE-2023-36761 | Media (6.5) | 20% | ⚠ Explotación activa | 12 sept 2023 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2023-35311 | Alta (7.5) | 16% | ⚠ Explotación activa | 11 jul 2023 | Microsoft Outlook Security Feature Bypass Vulnerability |
| CVE-2023-23397 | Crítica (9.8) | 97% | ⚠ Explotación activa | 14 mar 2023 | Microsoft Outlook Elevation of Privilege Vulnerability |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-42832 | Media (5.5) | 0.31% | — | 12 may 2026 | Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. |
| CVE-2026-42831 | Alta (7.8) | 0.47% | — | 12 may 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-40421 | Media (4.3) | 0.70% | — | 12 may 2026 | Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
| CVE-2026-40420 | Alta (8.8) | 0.30% | — | 12 may 2026 | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. |
| CVE-2026-40419 | Alta (7.8) | 0.33% | — | 12 may 2026 | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. |
| CVE-2026-40418 | Alta (7.8) | 0.33% | — | 12 may 2026 | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. |
| CVE-2026-40367 | Alta (8.4) | 0.45% | — | 12 may 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-40366 | Alta (8.4) | 0.36% | — | 12 may 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-40364 | Alta (8.4) | 0.36% | — | 12 may 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-40363 | Alta (8.4) | 0.36% | — | 12 may 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-40362 | Alta (7.8) | 0.47% | — | 12 may 2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-40361 | Alta (8.4) | 0.36% | — | 12 may 2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-40360 | Alta (7.8) | 0.47% | — | 12 may 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-40359 | Alta (7.8) | 0.47% | — | 12 may 2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-40358 | Alta (8.4) | 0.36% | — | 12 may 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-35440 | Media (5.5) | 0.55% | — | 12 may 2026 | Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
| CVE-2026-35436 | Alta (8.8) | 0.30% | — | 12 may 2026 | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. |
| CVE-2026-33822 | Media (6.1) | 0.46% | — | 14 abr 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
| CVE-2026-33115 | Alta (8.4) | 0.36% | — | 14 abr 2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-33114 | Alta (8.4) | 0.36% | — | 14 abr 2026 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-33095 | Alta (7.8) | 0.47% | — | 14 abr 2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-32200 | Alta (7.8) | 0.47% | — | 14 abr 2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
| CVE-2026-32199 | Alta (7.8) | 0.47% | — | 14 abr 2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-32198 | Alta (7.8) | 0.47% | — | 14 abr 2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-32197 | Alta (7.8) | 0.47% | — | 14 abr 2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-32190 | Alta (8.4) | 0.36% | — | 14 abr 2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-32189 | Alta (7.8) | 0.47% | — | 14 abr 2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-32188 | Alta (7.1) | 0.53% | — | 14 abr 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-23657 | Alta (7.8) | 0.41% | — | 14 abr 2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-26113 | Alta (7.8) | 0.41% | — | 10 mar 2026 | Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.