Microsoft Vulnerabilities and Affected Products
Vulnerabilities associated with Microsoft Office for Universal.
Products
Clear product- Windows Server 20194,131 vulnerabilities
- Windows Server 2019 (Server Core installation)4,034 vulnerabilities
- Windows 10 Version 18093,762 vulnerabilities
- Windows Server 20163,677 vulnerabilities
- Windows Server 20223,485 vulnerabilities
- Windows Server 2016 (Server Core installation)3,473 vulnerabilities
- Windows 10 Version 16073,184 vulnerabilities
- Windows 10 Version 21H23,063 vulnerabilities
- Windows Server 2012 R22,998 vulnerabilities
- Windows Server 2012 R2 (Server Core installation)2,853 vulnerabilities
- Windows Server 20122,824 vulnerabilities
- Windows Server 2012 (Server Core installation)2,691 vulnerabilities
- Windows 10 Version 22H22,565 vulnerabilities
- Windows 10 Version 15072,277 vulnerabilities
- Windows 11 Version 24H21,924 vulnerabilities
- Windows Server 20251,917 vulnerabilities
- Windows Server 2025 (Server Core installation)1,917 vulnerabilities
- Windows Server 2008 R2 Service Pack 11,874 vulnerabilities
- Windows Server 2008 R2 Service Pack 1 (Server Core installation)1,860 vulnerabilities
- Windows 11 Version 23H21,845 vulnerabilities
- Windows 11 version 22H21,776 vulnerabilities
- Windows Server 2022, 23H2 Edition (Server Core installation)1,725 vulnerabilities
- Windows Server 2008 Service Pack 2 (Server Core installation)1,667 vulnerabilities
- Windows Server 2008 Service Pack 21,664 vulnerabilities
- Windows 11 version 21H21,560 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-53766CRITICAL | GDI+ Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. CWE-122Aug 12, 2025 | CVSS9.8v3.1 | EPSS7.18% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-53732HIGH | Microsoft Office Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | CVSS7.8v3.1 | EPSS0.487% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-30388HIGH | Windows Graphics Component Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | CVSS7.8v3.1 | EPSS3.65% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-26687HIGH | Win32k Elevation of Privilege VulnerabilityUse after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. CWE-416Apr 8, 2025 | CVSS7.5v3.1 | EPSS1.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-21338HIGH | GDI+ Remote Code Execution VulnerabilityGDI+ Remote Code Execution Vulnerability CWE-190Jan 14, 2025 | CVSS7.8v3.1 | EPSS0.479% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38250HIGH | Windows Graphics Component Elevation of Privilege VulnerabilityWindows Graphics Component Elevation of Privilege Vulnerability CWE-126Sep 10, 2024 | CVSS7.8v3.1 | EPSS0.699% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-36565HIGH | Microsoft Office Graphics Elevation of Privilege VulnerabilityMicrosoft Office Graphics Elevation of Privilege Vulnerability CWE-416Oct 10, 2023 | CVSS7.0v3.1 | EPSS0.417% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-33158HIGH | Microsoft Excel Remote Code Execution VulnerabilityMicrosoft Excel Remote Code Execution Vulnerability CWE-191Jul 11, 2023 | CVSS7.8v3.1 | EPSS0.631% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-24910HIGH | Windows Graphics Component Elevation of Privilege VulnerabilityWindows Graphics Component Elevation of Privilege Vulnerability CWE-476Mar 14, 2023 | CVSS7.8v3.1 | EPSS0.393% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21823HIGH | Windows Graphics Component Remote Code Execution VulnerabilityWindows Graphics Component Remote Code Execution Vulnerability CWE-190Feb 14, 2023 | CVSS7.8v3.1 | EPSS5.56% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |