Product:

Office

(Microsoft)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 838
Date Id Summary Products Score Patch Annotated
2019-08-14 CVE-2019-1155 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory. Office, Office_365_proplus, Windows_10, Windows_7, Windows_8\.1, Windows_rt_8\.1, Windows_server_2008, Windows_server_2012, Windows_server_2016, Windows_server_2019 7.8
2019-08-14 CVE-2019-1204 An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a local or remote message store (over SMB). To exploit the vulnerability, the attacker could send a specially crafted email to a victim. Outlook would then attempt to open a pre-configured message store contained in the... Office, Office_365_proplus, Outlook 4.3
2019-08-14 CVE-2019-1199 A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose... Office, Office_365_proplus 7.8
2019-08-14 CVE-2019-1200 A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. To exploit the vulnerability, a user must open a specially crafted file with an affected... Office, Office_365_proplus, Outlook 7.8
2019-08-14 CVE-2019-1201 A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. The file could then take actions on behalf of the logged-on user with the same permissions as the current user. To exploit the vulnerability, a user must open a specially crafted file with an affected version of... Office, Office_365_proplus, Office_online_server, Office_web_apps, Office_web_apps_server, Sharepoint_enterprise_server, Sharepoint_server, Word 7.8
2023-01-10 CVE-2023-21734 Microsoft Office Remote Code Execution Vulnerability 365_apps, Office, Office_long_term_servicing_channel 7.8
2023-01-10 CVE-2023-21735 Microsoft Office Remote Code Execution Vulnerability 365_apps, Office, Office_long_term_servicing_channel 7.8
2023-01-10 CVE-2023-21737 Microsoft Office Visio Remote Code Execution Vulnerability 365_apps, Office, Office_long_term_servicing_channel, Visio 7.8
2023-01-10 CVE-2023-21736 Microsoft Office Visio Remote Code Execution Vulnerability 365_apps, Office, Office_long_term_servicing_channel, Visio 7.8
2023-01-10 CVE-2023-21738 Microsoft Office Visio Remote Code Execution Vulnerability 365_apps, Office, Office_long_term_servicing_channel 7.8