Known Vulnerabilities for Office by Microsoft Corporation
Listed below are 10 of the newest known vulnerabilities associated with "Office" by "Microsoft Corporation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-42832 json | Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-42831 json | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-41102 json | Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally. | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-41101 json | Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-40421 json | External control of file name or path in Microsoft Office Word allows an unauthorized attacker to disclose information over a... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-40420 json | Improper access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-40419 json | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-40418 json | Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-40368 json | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-40367 json | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | Not Provided | 2026-05-12 | 2026-05-12 |