22 results (0.008 seconds)

CVSS: 7.8EPSS: 0%CPEs: 3EXPL: 0

14 Jan 2025 — Microsoft Office OneNote Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21402 • CWE-641: Improper Restriction of Names for Files and Other Resources •

CVSS: 7.8EPSS: 0%CPEs: 3EXPL: 0

14 Jan 2025 — Microsoft Outlook Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21361 • CWE-641: Improper Restriction of Names for Files and Other Resources •

CVSS: 7.8EPSS: 0%CPEs: 32EXPL: 0

14 Jan 2025 — GDI+ Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21338 • CWE-190: Integer Overflow or Wraparound •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

14 Jan 2025 — Microsoft Word Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Office Word. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DOCX files. The issue results from the lack of proper initialization of a pointer prior to accessing it. An attacker can leverage this vulnerability to execute c... • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21363 • CWE-822: Untrusted Pointer Dereference •

CVSS: 8.4EPSS: 0%CPEs: 4EXPL: 0

14 Jan 2025 — Microsoft Excel Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21362 • CWE-416: Use After Free •

CVSS: 8.4EPSS: 0%CPEs: 3EXPL: 0

14 Jan 2025 — Microsoft Excel Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21354 • CWE-822: Untrusted Pointer Dereference •

CVSS: 5.5EPSS: 0%CPEs: 5EXPL: 0

10 Dec 2024 — Microsoft Office Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49065 • CWE-125: Out-of-bounds Read •

CVSS: 7.8EPSS: 0%CPEs: 3EXPL: 0

10 Dec 2024 — Microsoft Excel Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49069 • CWE-416: Use After Free •

CVSS: 7.6EPSS: 0%CPEs: 3EXPL: 0

12 Nov 2024 — Microsoft Word Security Feature Bypass Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49033 • CWE-20: Improper Input Validation •

CVSS: 7.8EPSS: 0%CPEs: 3EXPL: 0

12 Nov 2024 — Microsoft Office Graphics Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Office PowerPoint. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PPTX files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker c... • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49032 • CWE-416: Use After Free •