« Volver al listado

Microsoft

Microsoft Office Long Term Servicing Channel: vulnerabilidades y CVE

Microsoft Office Long Term Servicing Channel tiene 367 vulnerabilidades publicadas, 93 de ellas en los últimos 12 meses. 6 son críticas y 8 figuran en el catálogo de explotación activa de CISA.

CVE367
Últimos 12 meses93
Críticas6
Explotadas activamente8

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-21514Alta (7.8)1.6%⚠ Explotación activa10 feb 2026
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-21509Alta (7.8)71%⚠ Explotación activa26 ene 2026
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
CVE-2024-21413Crítica (9.8)95%⚠ Explotación activa13 feb 2024
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2024-38226Alta (7.3)2.7%⚠ Explotación activa10 sept 2024
Microsoft Publisher Security Feature Bypass Vulnerability
CVE-2024-38189Alta (8.8)8.2%⚠ Explotación activa13 ago 2024
Microsoft Project Remote Code Execution Vulnerability
CVE-2023-36761Media (6.5)20%⚠ Explotación activa12 sept 2023
Microsoft Word Information Disclosure Vulnerability
CVE-2023-35311Alta (7.5)16%⚠ Explotación activa11 jul 2023
Microsoft Outlook Security Feature Bypass Vulnerability
CVE-2023-23397Crítica (9.8)97%⚠ Explotación activa14 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-42832Media (5.5)0.31%—12 may 2026
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
CVE-2026-42831Alta (7.8)0.47%—12 may 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40421Media (4.3)0.70%—12 may 2026
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-40420Alta (8.8)0.30%—12 may 2026
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-40419Alta (7.8)0.33%—12 may 2026
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-40418Alta (7.8)0.33%—12 may 2026
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-40367Alta (8.4)0.45%—12 may 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40366Alta (8.4)0.36%—12 may 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40364Alta (8.4)0.36%—12 may 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40363Alta (8.4)0.36%—12 may 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40362Alta (7.8)0.47%—12 may 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-40361Alta (8.4)0.36%—12 may 2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40360Alta (7.8)0.47%—12 may 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-40359Alta (7.8)0.47%—12 may 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-40358Alta (8.4)0.36%—12 may 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-35440Media (5.5)0.55%—12 may 2026
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-35436Alta (8.8)0.30%—12 may 2026
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-33822Media (6.1)0.46%—14 abr 2026
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-33115Alta (8.4)0.36%—14 abr 2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-33114Alta (8.4)0.36%—14 abr 2026
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-33095Alta (7.8)0.47%—14 abr 2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-32200Alta (7.8)0.47%—14 abr 2026
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2026-32199Alta (7.8)0.47%—14 abr 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-32198Alta (7.8)0.47%—14 abr 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-32197Alta (7.8)0.47%—14 abr 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-32190Alta (8.4)0.36%—14 abr 2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-32189Alta (7.8)0.47%—14 abr 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-32188Alta (7.1)0.53%—14 abr 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-23657Alta (7.8)0.41%—14 abr 2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-26113Alta (7.8)0.41%—10 mar 2026
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter192
  2. T1203 Exploitation for Client Execution167
  3. T1068 Exploitation for Privilege Escalation44
  4. T1005 Data from Local System9
  5. T1190 Exploit Public-Facing Application5
  6. T1078 Valid Accounts3

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

📰 Noticias relacionadas

Otros productos de Microsoft