Showing 25 vulnerabilities on this page for Microsoft Office 2019

Signals CISA KEV Ransomware Nuclei
Microsoft vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Microsoft Office Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CWE-122Aug 11, 2026
CVSS8.4v3.1EPSS0.35%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Excel Remote Code Execution Vulnerability

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CWE-121Aug 11, 2026
CVSS7.8v3.1EPSS0.404%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Excel Remote Code Execution Vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CWE-125Aug 11, 2026
CVSS7.8v3.1EPSS0.404%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Excel Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CWE-122Aug 11, 2026
CVSS7.8v3.1EPSS0.404%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Excel Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CWE-122Aug 11, 2026
CVSS7.8v3.1EPSS0.325%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Excel Remote Code Execution Vulnerability

Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CWE-122CWE-197Aug 11, 2026
CVSS7.8v3.1EPSS0.352%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Excel Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CWE-843Aug 11, 2026
CVSS7.8v3.1EPSS0.303%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Excel Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CWE-122Aug 11, 2026
CVSS7.8v3.1EPSS0.325%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Excel Information Disclosure Vulnerability

Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CWE-908Aug 11, 2026
CVSS5.5v3.1EPSS0.345%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Excel Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CWE-125Aug 11, 2026
CVSS5.5v3.1EPSS0.447%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Office Graphics Component Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CWE-125Aug 11, 2026
CVSS5.5v3.1EPSS0.352%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Office Word Information Disclosure Vulnerability

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CWE-122Aug 11, 2026
CVSS5.5v3.1EPSS0.352%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Office Graphics Component Remote Code Execution Vulnerability

Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CWE-121Aug 11, 2026
CVSS7.8v3.1EPSS0.359%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Office Word Information Disclosure Vulnerability

Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CWE-125CWE-193Aug 11, 2026
CVSS5.5v3.1EPSS0.529%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Outlook Spoofing Vulnerability

Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

CWE-522Aug 11, 2026
CVSS4.3v3.1EPSS0.614%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Access Remote Code Execution Vulnerability

Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.

CWE-121Aug 11, 2026
CVSS7.8v3.1EPSS0.31%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Office Word Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CWE-125Aug 11, 2026
CVSS5.5v3.1EPSS0.352%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Access Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.

CWE-122Aug 11, 2026
CVSS7.8v3.1EPSS0.31%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Office Word Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CWE-122Aug 11, 2026
CVSS7.8v3.1EPSS0.31%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Access Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.

CWE-122Aug 11, 2026
CVSS7.8v3.1EPSS0.401%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Access Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.

CWE-122Aug 11, 2026
CVSS7.8v3.1EPSS0.31%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Office Remote Code Execution Vulnerability

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.

CWE-122CWE-190Aug 11, 2026
CVSS7.8v3.1EPSS0.348%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Access Remote Code Execution Vulnerability

Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.

CWE-121Aug 11, 2026
CVSS7.8v3.1EPSS0.31%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Office Remote Code Execution Vulnerability

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

CWE-822Aug 11, 2026
CVSS7.8v3.1EPSS0.348%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Office Remote Code Execution Vulnerability

Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS7.8v3.1EPSS0.348%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX