Microsoft Vulnerabilities and Affected Products
Vulnerabilities associated with Microsoft Office for Android.
Products
Clear product- Windows Server 20194,131 vulnerabilities
- Windows Server 2019 (Server Core installation)4,034 vulnerabilities
- Windows 10 Version 18093,762 vulnerabilities
- Windows Server 20163,677 vulnerabilities
- Windows Server 20223,485 vulnerabilities
- Windows Server 2016 (Server Core installation)3,473 vulnerabilities
- Windows 10 Version 16073,184 vulnerabilities
- Windows 10 Version 21H23,063 vulnerabilities
- Windows Server 2012 R22,998 vulnerabilities
- Windows Server 2012 R2 (Server Core installation)2,853 vulnerabilities
- Windows Server 20122,824 vulnerabilities
- Windows Server 2012 (Server Core installation)2,691 vulnerabilities
- Windows 10 Version 22H22,565 vulnerabilities
- Windows 10 Version 15072,277 vulnerabilities
- Windows 11 Version 24H21,924 vulnerabilities
- Windows Server 20251,917 vulnerabilities
- Windows Server 2025 (Server Core installation)1,917 vulnerabilities
- Windows Server 2008 R2 Service Pack 11,874 vulnerabilities
- Windows Server 2008 R2 Service Pack 1 (Server Core installation)1,860 vulnerabilities
- Windows 11 Version 23H21,845 vulnerabilities
- Windows 11 version 22H21,776 vulnerabilities
- Windows Server 2022, 23H2 Edition (Server Core installation)1,725 vulnerabilities
- Windows Server 2008 Service Pack 2 (Server Core installation)1,667 vulnerabilities
- Windows Server 2008 Service Pack 21,664 vulnerabilities
- Windows 11 version 21H21,560 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-50387HIGH | Windows GDI Elevation of Privilege VulnerabilityStack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally. CWE-121Jul 14, 2026 | CVSS7.8v3.1 | EPSS1.92% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-45463HIGH | Microsoft Office Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | CVSS8.4v3.1 | EPSS0.364% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-45461HIGH | Microsoft Office Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | CVSS8.4v3.1 | EPSS0.39% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-45460MEDIUM | Microsoft Office Information Disclosure VulnerabilityOut-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. CWE-126Jun 9, 2026 | CVSS4.7v3.1 | EPSS0.357% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-45474HIGH | Microsoft Office Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | CVSS8.4v3.1 | EPSS0.364% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-45472HIGH | Microsoft Office Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | CVSS8.4v3.1 | EPSS0.364% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-42831HIGH | Microsoft Office Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. CWE-122May 12, 2026 | CVSS7.8v3.1 | EPSS0.437% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40363HIGH | Microsoft Office Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. CWE-122May 12, 2026 | CVSS8.4v3.1 | EPSS0.383% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-26110HIGH | Microsoft Office Remote Code Execution VulnerabilityAccess of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. CWE-843Mar 10, 2026 | CVSS8.4v3.1 | EPSS0.49% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-26134HIGH | Microsoft Office Elevation of Privilege VulnerabilityInteger overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally. | CVSS7.8v3.1 | EPSS0.353% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25180MEDIUM | Windows Graphics Component Information Disclosure VulnerabilityOut-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally. CWE-125Mar 10, 2026 | CVSS5.5v3.1 | EPSS0.655% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-24285HIGH | Win32k Elevation of Privilege VulnerabilityUse after free in Windows Win32K allows an authorized attacker to elevate privileges locally. CWE-416Mar 10, 2026 | CVSS7.0v3.1 | EPSS0.462% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20846HIGH | GDI+ Denial of Service VulnerabilityBuffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network. CWE-126Feb 10, 2026 | CVSS7.5v3.1 | EPSS1.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62557HIGH | Microsoft Office Remote Code Execution VulnerabilityUse after free in Microsoft Office allows an unauthorized attacker to execute code locally. CWE-416Dec 9, 2025 | CVSS8.4v3.1 | EPSS0.412% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62554HIGH | Microsoft Office Remote Code Execution VulnerabilityAccess of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. CWE-843Dec 9, 2025 | CVSS8.4v3.1 | EPSS0.421% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-60724CRITICAL | GDI+ Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. CWE-122Nov 11, 2025 | CVSS9.8v3.1 | EPSS5.92% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62199HIGH | Microsoft Office Remote Code Execution VulnerabilityUse after free in Microsoft Office allows an unauthorized attacker to execute code locally. CWE-416Nov 11, 2025 | CVSS7.8v3.1 | EPSS0.76% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59227HIGH | Microsoft Office Remote Code Execution VulnerabilityUse after free in Microsoft Office allows an unauthorized attacker to execute code locally. CWE-416Oct 14, 2025 | CVSS7.8v3.1 | EPSS0.481% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59234HIGH | Microsoft Office Remote Code Execution VulnerabilityUse after free in Microsoft Office allows an unauthorized attacker to execute code locally. CWE-416Oct 14, 2025 | CVSS7.8v3.1 | EPSS0.563% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-53799MEDIUM | Windows Imaging Component Information Disclosure VulnerabilityUse of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally. CWE-908Sep 9, 2025 | CVSS5.5v3.1 | EPSS0.782% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-53766CRITICAL | GDI+ Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. CWE-122Aug 12, 2025 | CVSS9.8v3.1 | EPSS7.18% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-53732HIGH | Microsoft Office Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | CVSS7.8v3.1 | EPSS0.487% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-49702HIGH | Microsoft Office Remote Code Execution VulnerabilityAccess of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. CWE-843Jul 8, 2025 | CVSS7.8v3.1 | EPSS0.516% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-49697HIGH | Microsoft Office Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. CWE-122Jul 8, 2025 | CVSS8.4v3.1 | EPSS0.465% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-49696HIGH | Microsoft Office Remote Code Execution VulnerabilityOut-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. | CVSS8.4v3.1 | EPSS0.556% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |