Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Office — Vulnerabilities & Security Advisories 20

All 20 CVE vulnerabilities found in Office, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of Common Weakness Enumeration (CWE) vulnerabilities associated with Microsoft Office. It serves as a centralized resource for security researchers, system administrators, and IT professionals seeking to understand the risk landscape surrounding this widely used productivity suite. The content collects documented security flaws, including buffer overflows, injection vulnerabilities, and remote code execution issues, spanning from early releases of Office 97 through to the latest Microsoft 365 versions. This historical breadth allows for a longitudinal analysis of how security postures have evolved across different product generations and update cycles. By consolidating data from various vendor advisories and independent security reports, the page ensures that users have access to a unified view of known defects without needing to navigate multiple disparate sources. Here, readers can track a vendor's advisories to stay informed about patching timelines and severity ratings. You can also understand a weakness class by seeing how specific CWE types manifest in different components of the Office ecosystem, such as Word, Excel, or Outlook. Furthermore, the page enables users to look up a product's vulnerability history, facilitating deeper investigations into past incidents and the effectiveness of previous remediation efforts. This structured approach supports informed decision-making regarding deployment, mitigation strategies, and upgrade planning within organizational environments.

Vendor: Microsoft Corporation

CVE IDTitleCVSSSeverityPublished
CVE-2023-7270 Local Privilege Escalation via MSI installer 7.8AIHighAI2024-06-27
CVE-2023-51598 Hancom Office Word DOC File Parsing Use-After-Free Remote Code Execution Vulnerability CWE-416 7.8 -2024-05-03
CVE-2023-50235 Hancom Office Show PPT File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability CWE-121 7.8 -2024-05-03
CVE-2023-50234 Hancom Office Cell XLS File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability CWE-121 7.8 -2024-05-03
CVE-2019-11828 Synology Office 跨站脚本漏洞 CWE-79 5.5 Medium2019-06-30
CVE-2018-8924 Synology Office Title Tootip 跨站脚本漏洞 CWE-79 5.4 -2018-06-05
CVE-2017-0106 Microsoft Office 缓冲区错误漏洞 7.8 -2017-04-12
CVE-2017-0197 Microsoft Office 安全漏洞 7.8 -2017-04-12
CVE-2017-0195 Microsoft Office 安全漏洞 6.1 -2017-04-12
CVE-2017-0194 Microsoft Office 信息泄露漏洞 5.5 -2017-04-12
CVE-2017-0006 Microsoft Office 安全漏洞 7.8 -2017-03-17
CVE-2017-0105 Microsoft Office 信息泄露漏洞 5.5 -2017-03-17
CVE-2017-0053 Microsoft Office 安全漏洞 7.8 -2017-03-17
CVE-2017-0052 Microsoft Office 安全漏洞 7.8 -2017-03-17
CVE-2017-0031 Microsoft Office 缓冲区错误漏洞 7.8 -2017-03-17
CVE-2017-0030 Microsoft Office 缓冲区错误漏洞 7.8 -2017-03-17
CVE-2017-0029 Microsoft Office 安全漏洞 5.5 -2017-03-17
CVE-2017-0027 Microsoft Office 信息泄露漏洞 5.5 -2017-03-17
CVE-2017-0020 Microsoft Office 安全漏洞 7.8 -2017-03-17
CVE-2017-0019 Microsoft Word 安全漏洞 7.8 -2017-03-17

All 20 known CVE vulnerabilities affecting Office with full Chinese analysis, references, and POCs where available.