Microsoft 365 Apps
By the Year
In 2021 there have been 18 vulnerabilities in Microsoft 365 Apps with an average score of 7.8 out of ten. Last year 365 Apps had 30 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in 365 Apps in 2021 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2021 is greater by 0.20.
Year | Vulnerabilities | Average Score |
---|---|---|
2021 | 18 | 7.76 |
2020 | 30 | 7.56 |
2019 | 0 | 0.00 |
2018 | 0 | 0.00 |
It may take a day or so for new 365 Apps vulnerabilities to show up. Additionally vulnerabilities may be tagged under a different product or component name.
Latest Microsoft 365 Apps Security Vulnerabilities
Microsoft Word Remote Code Execution Vulnerability
CVE-2021-28453
7.8 - High
- April 13, 2021
Microsoft Word Remote Code Execution Vulnerability
Microsoft Outlook Memory Corruption Vulnerability
CVE-2021-28452
7.8 - High
- April 13, 2021
Microsoft Outlook Memory Corruption Vulnerability
Buffer Overflow
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique
CVE-2021-28451
7.8 - High
- April 13, 2021
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-28454.
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique
CVE-2021-27054
7.8 - High
- March 11, 2021
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-27053.
Microsoft Office Remote Code Execution Vulnerability This CVE ID is unique
CVE-2021-24108
7.8 - High
- March 11, 2021
Microsoft Office Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-27057, CVE-2021-27059.
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique
CVE-2021-27053
7.8 - High
- March 11, 2021
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-27054.
Microsoft Visio Security Feature Bypass Vulnerability
CVE-2021-27055
7 - High
- March 11, 2021
Microsoft Visio Security Feature Bypass Vulnerability
Microsoft PowerPoint Remote Code Execution Vulnerability
CVE-2021-27056
7.8 - High
- March 11, 2021
Microsoft PowerPoint Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability This CVE ID is unique
CVE-2021-27057
7.8 - High
- March 11, 2021
Microsoft Office Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-24108, CVE-2021-27059.
Microsoft Office ClickToRun Remote Code Execution Vulnerability
CVE-2021-27058
7.8 - High
- March 11, 2021
Microsoft Office ClickToRun Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique
CVE-2021-24067
7.8 - High
- February 25, 2021
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-24068, CVE-2021-24069, CVE-2021-24070.
Dangling pointer
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique
CVE-2021-24069
7.8 - High
- February 25, 2021
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-24067, CVE-2021-24068, CVE-2021-24070.
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique
CVE-2021-24070
7.8 - High
- February 25, 2021
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-24067, CVE-2021-24068, CVE-2021-24069.
Dangling pointer
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique
CVE-2021-1714
7.8 - High
- January 12, 2021
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1713.
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique
CVE-2021-1713
7.8 - High
- January 12, 2021
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1714.
Buffer Overflow
Microsoft Word Remote Code Execution Vulnerability This CVE ID is unique
CVE-2021-1715
7.8 - High
- January 12, 2021
Microsoft Word Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1716.
Memory Corruption
Microsoft Word Remote Code Execution Vulnerability This CVE ID is unique
CVE-2021-1716
7.8 - High
- January 12, 2021
Microsoft Word Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1715.
Microsoft Office Remote Code Execution Vulnerability
CVE-2021-1711
7.8 - High
- January 12, 2021
Microsoft Office Remote Code Execution Vulnerability
Microsoft Excel Security Feature Bypass Vulnerability
CVE-2020-17130
6.5 - Medium
- December 10, 2020
Microsoft Excel Security Feature Bypass Vulnerability
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique
CVE-2020-17129
7.8 - High
- December 10, 2020
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2020-17122, CVE-2020-17123, CVE-2020-17125, CVE-2020-17127, CVE-2020-17128.
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique
CVE-2020-17128
7.8 - High
- December 10, 2020
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2020-17122, CVE-2020-17123, CVE-2020-17125, CVE-2020-17127, CVE-2020-17129.
Microsoft Excel Information Disclosure Vulnerability
CVE-2020-17126
5.5 - Medium
- December 10, 2020
Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique
CVE-2020-17125
7.8 - High
- December 10, 2020
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2020-17122, CVE-2020-17123, CVE-2020-17127, CVE-2020-17128, CVE-2020-17129.
Microsoft PowerPoint Remote Code Execution Vulnerability
CVE-2020-17124
7.8 - High
- December 10, 2020
Microsoft PowerPoint Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique
CVE-2020-17123
7.8 - High
- December 10, 2020
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2020-17122, CVE-2020-17125, CVE-2020-17127, CVE-2020-17128, CVE-2020-17129.
Microsoft Outlook Information Disclosure Vulnerability
CVE-2020-17119
7.5 - High
- December 10, 2020
Microsoft Outlook Information Disclosure Vulnerability
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique
CVE-2020-17065
7.8 - High
- November 11, 2020
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2020-17019, CVE-2020-17064, CVE-2020-17066.
Microsoft Excel Security Feature Bypass Vulnerability
CVE-2020-17067
7.8 - High
- November 11, 2020
Microsoft Excel Security Feature Bypass Vulnerability
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique
CVE-2020-17064
7.8 - High
- November 11, 2020
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2020-17019, CVE-2020-17065, CVE-2020-17066.
Microsoft Office Online Spoofing Vulnerability
CVE-2020-17063
5.4 - Medium
- November 11, 2020
Microsoft Office Online Spoofing Vulnerability
Improper Input Validation
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
CVE-2020-17062
7.8 - High
- November 11, 2020
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Microsoft Word Security Feature Bypass Vulnerability
CVE-2020-17020
5.5 - Medium
- November 11, 2020
Microsoft Word Security Feature Bypass Vulnerability
authentification
A remote code execution vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory
CVE-2020-16947
8.8 - High
- October 16, 2020
A remote code execution vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory, aka 'Microsoft Outlook Remote Code Execution Vulnerability'.
Memory Corruption
A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.An attacker who successfully exploited the vulnerability
CVE-2020-16918
7.8 - High
- October 16, 2020
A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.An attacker who successfully exploited the vulnerability would gain execution on a victim system.The security update addresses the vulnerability by correcting how the Base3D rendering engine handles memory., aka 'Base3D Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-17003.
An elevation of privilege vulnerability exists in the way
CVE-2020-16928
7.8 - High
- October 16, 2020
An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files, aka 'Microsoft Office Click-to-Run Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16934, CVE-2020-16955.
Improper Privilege Management
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory
CVE-2020-16929
7.8 - High
- October 16, 2020
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-16930, CVE-2020-16931, CVE-2020-16932.
Dangling pointer
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory
CVE-2020-16930
7.8 - High
- October 16, 2020
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-16929, CVE-2020-16931, CVE-2020-16932.
Memory Corruption
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory
CVE-2020-16931
7.8 - High
- October 16, 2020
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-16929, CVE-2020-16930, CVE-2020-16932.
Use of Uninitialized Resource
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory
CVE-2020-16932
7.8 - High
- October 16, 2020
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-16929, CVE-2020-16930, CVE-2020-16931.
Buffer Overflow
A security feature bypass vulnerability exists in Microsoft Word software when it fails to properly handle .LNK files
CVE-2020-16933
8.8 - High
- October 16, 2020
A security feature bypass vulnerability exists in Microsoft Word software when it fails to properly handle .LNK files, aka 'Microsoft Word Security Feature Bypass Vulnerability'.
Improper Handling of Exceptional Conditions
An elevation of privilege vulnerability exists in the way
CVE-2020-16934
7.8 - High
- October 16, 2020
An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files, aka 'Microsoft Office Click-to-Run Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16928, CVE-2020-16955.
Improper Privilege Management
A denial of service vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory
CVE-2020-16949
7.5 - High
- October 16, 2020
A denial of service vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory, aka 'Microsoft Outlook Denial of Service Vulnerability'.
Memory Leak
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory
CVE-2020-16954
7.8 - High
- October 16, 2020
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Remote Code Execution Vulnerability'.
Buffer Overflow
An elevation of privilege vulnerability exists in the way
CVE-2020-16955
7.8 - High
- October 16, 2020
An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files, aka 'Microsoft Office Click-to-Run Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16928, CVE-2020-16934.
Improper Input Validation
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory
CVE-2020-16957
7.8 - High
- October 16, 2020
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'.
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory
CVE-2020-1563
7.8 - High
- August 17, 2020
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Remote Code Execution Vulnerability'.
Buffer Overflow
An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory
CVE-2020-1445
5.5 - Medium
- July 14, 2020
An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1342.
Information Disclosure
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory
CVE-2020-0901
9.8 - Critical
- May 21, 2020
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
Buffer Overflow
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Microsoft Office or by Microsoft? Click the Watch button to subscribe.
