VendorsMicrosoftwordany version
Vulnerabilities

Microsoft Word any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2008-0109
Word in Microsoft Office 2000 SP3, XP SP3, Office 2003 SP2, and Office Word Viewer 2003 allows remote attackers to execute arbitrary code via crafted fields within the File Information Block (FIB) of a Word file, which triggers length calculation errors and memory corruption.
Published 2008-02-12 · Modified
9.3EPSS 0.309
CVE-2022-26903
Windows Graphics Component Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.3EPSS 0.027
CVE-2020-1223
A remote code execution vulnerability exists when Microsoft Word for Android fails to properly handle certain files.To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file.The update addresses the vulnerability by correcting how Microsoft Word for Android handles specially crafted URL files., aka 'Word for Android Remote Code Execution Vulnerability'.
Published 2020-06-09 · Modified
8.8EPSS 0.080
CVE-2026-44803
Windows Graphics Component Remote Code Execution Vulnerability
Published 2026-06-09 · Analyzed
7.8EPSS 0.005
CVE-2026-44812
Windows Graphics Component Remote Code Execution Vulnerability
Published 2026-06-09 · Analyzed
7.8EPSS 0.005
CVE-2026-42832
Microsoft Office Spoofing Vulnerability
Published 2026-05-12 · Analyzed
7.7EPSS 0.003
CVE-2026-26133
M365 Copilot Information Disclosure Vulnerability
Published 2026-03-13 · Modified
7.1EPSS 0.005
CVE-2026-45649
Office for Android Spoofing Vulnerability
Published 2026-06-09 · Analyzed
7.1EPSS 0.004
CVE-2026-41101
Microsoft Word for Android Spoofing Vulnerability
Published 2026-05-12 · Analyzed
7.1EPSS 0.003
CVE-2002-1143
Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."
Published 2003-04-03 · Modified
5.02 PoCEPSS 0.536
CVE-2001-0501
Microsoft Word 2002 and earlier allows attackers to automatically execute macros without warning the user by embedding the macros in a manner that escapes detection by the security scanner.
Published 2002-03-09 · Modified
4.6EPSS 0.017
CVE-2012-0765
Multiple cross-site scripting (XSS) vulnerabilities in Adobe RoboHelp 8 and 9 for Word allow remote attackers to inject arbitrary web script or HTML via a crafted URL, related to certain .htm files in (1) template_stock and (2) template_csh directories.
Published 2012-02-15 · Modified
4.3EPSS 0.026
CVE-2005-1683
Buffer overflow in winword.exe 10.2627.6714 and earlier in Microsoft Word for the Macintosh, before SP3 for Word 2002, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted mcw file.
Published 2005-05-25 · Modified
2.6EPSS 0.146