FAIL › dossier
Office
PRODUCT· dossier confidence 20%
Microsoft Office is a dominant productivity suite but has a documented history of critical and high-severity remote code execution vulnerabilities, requiring vigilant patch management to prevent exploitation. Recent events show active exploitation of zero-day flaws in identity and collaboration services, highlighting persistent security gaps despite large-scale patching efforts.
PROFILE
CategorySoftwareWhat they doMicrosoft Corporation develops and sells productivity software, operating systems, and cloud computing services, with Microsoft Office being its flagship productivity suite.
Websitehttps://www.microsoft.com ↗
SECURITY POSTURE
Microsoft maintains a proactive patching program but suffers from a high volume of critical and high-severity remote code execution (RCE) vulnerabilities across its Office suite, often requiring urgent patching cycles to mitigate exploitation risks.
Notable failures
- CVE-2021-38646 (critical RCE in Office Access)
- CVE-2017-11882 (critical RCE in Office)
- CVE-2026-56155 (actively exploited AD FS zero-day)
Patterns: repeated unpatched edge-device RCEs; memory corruption leading to RCE; security feature bypasses via untrusted inputs
FAILURE HISTORY · 31
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2017-11882 | critical | A Microsoft Office memory corruption vulnerability allowed for remote code execution and was actively exploited, likely contributing to ransomware attacks. |
| 2026-04-14 | CVE-2009-0238 | high | Microsoft Office Excel contains a remote code execution vulnerability that allows attackers to take complete control of a system by opening a specially crafted file. |
| 2022-03-03 | CVE-2012-1856 | high | A 12-year-old unpatched Microsoft Office ActiveX vulnerability in MSCOMCTL.OCX allows remote attackers to execute arbitrary code via crafted documents or web pages. |
| 2022-03-03 | CVE-2010-3333 | high | A stack-based buffer overflow in Microsoft Office's RTF parser allowed remote code execution, and it was actively exploited in the wild. |
| 2022-06-08 | CVE-2009-0557 | high | A malformed Excel file could trigger remote code execution in Microsoft Office via an object record corruption flaw. |
| 2022-03-03 | CVE-2016-7193 | high | A memory corruption flaw in Microsoft Office allowed remote code execution and was actively exploited in the wild. |
| 2022-02-25 | CVE-2017-8570 | high | Microsoft Office contained an unpatched remote code execution vulnerability that was actively exploited in the wild. |
| 2021-11-03 | CVE-2018-0802 | high | A memory corruption flaw in Microsoft Office allowed remote code execution when chained with another vulnerability, and was actively exploited in the wild. |
| 2022-03-28 | CVE-2015-1770 | high | A remote code execution vulnerability in Microsoft Office allowed attackers to execute arbitrary code via a crafted document. |
| 2022-03-03 | CVE-2017-0261 | high | Microsoft Office contained a use-after-free vulnerability allowing remote code execution that was actively exploited in the wild. |
| 2022-03-03 | CVE-2015-2545 | high | A malformed EPS file in Microsoft Office allowed remote attackers to execute arbitrary code, and the vulnerability was actively exploited in the wild. |
| 2022-03-03 | CVE-2017-11826 | high | Microsoft Office had a remote code execution vulnerability that was actively exploited in the wild. |
| 2022-02-10 | CVE-2017-0262 | high | Microsoft Office contained a remote code execution vulnerability that was actively exploited in the wild. |
| 2021-11-17 | CVE-2021-42292 | high | A local user can bypass Excel security features to execute arbitrary code. |
| 2021-11-03 | CVE-2018-0798 | high | Microsoft Office memory corruption flaw allows remote code execution and is actively exploited in the wild. |
| 2021-11-03 | CVE-2021-27059 | high | Microsoft Office contained an unpatched remote code execution vulnerability that was actively exploited in the wild. |
| 2021-11-03 | CVE-2016-3235 | high | Microsoft Office OLE DLL side loading vulnerability allowed remote code execution by improperly validating input before loading libraries. |
| 2021-11-03 | CVE-2015-1641 | high | A memory corruption flaw in Microsoft Office allowed remote code execution when processing rich text format files. |
| 2026-02-10 | CVE-2026-21514 | high | Authorized attacker could elevate privileges in Microsoft Office Word due to reliance on untrusted inputs |
| 2026-01-26 | CVE-2026-21509 | high | Microsoft Office flaw exploited, users advised to transition to supported versions. |
| 2026-01-07 | CVE-2009-0556 | high | Microsoft Office PowerPoint allowed remote code execution through a vulnerability in its software. |
| 2025-08-12 | CVE-2007-0671 | high | Microsoft Excel allowed remote code execution through malicious files. |
| 2023-03-14 | CVE-2023-23397 | high | Microsoft Office Outlook allows NTLM Relay attacks |
| 2023-02-14 | CVE-2023-21715 | high | Microsoft Publisher flaw exploited in wild |
| 2022-06-08 | CVE-2009-0563 | high | A 2009 Microsoft Office buffer overflow flaw allowed remote attackers to execute code via crafted Word documents. |
| 2022-03-28 | CVE-2021-38646 | critical | A Microsoft Office vulnerability allowed authenticated users to inject SQL and potentially execute arbitrary code remotely, actively exploited in ransomware attacks. |
| 2022-03-03 | CVE-2015-1642 | high | A memory corruption flaw in Microsoft Office allowed remote attackers to execute arbitrary code via a crafted document. |
| 2021-11-03 | CVE-2017-11774 | high | A memory handling flaw in Microsoft Outlook allowed attackers to bypass security features and execute arbitrary commands. |
| 2022-06-08 | CVE-2013-1331 | high | A Microsoft Office buffer overflow vulnerability allows remote code execution via crafted PNG files, and is currently being exploited in the wild. |
| 2023-02-14 | CVE-2023-21716 | critical | CVE-2023-21716: Microsoft Word Remote Code Execution Vulnerability |
| 2020-05-21 | CVE-2020-0901 | critical | CVE-2020-0901: A remote code execution vulnerability exists in Microsoft Excel software when th |
DOSSIER SOURCES
- Amazon (company) - Wikipedia · en.wikipedia.org
- Microsoft Corporation | History, Software, Cloud, & AI Innovations ... · www.britannica.com
- Microsoft Patch Tuesday July 2026: AD FS & SharePoint Zero-Days · sanjayseth.com
- Cyber security breach announced at Jennings County Clerk's Office · www.localnewsdigital.com
- History, Cars, Elon Musk, & Headquarters - Britannica Money · www.britannica.com
- Bank of England | History, Headquarters, & Facts | Britannica Money · www.britannica.com
- OpenAI, Inc. Headquarters and Office Locations Worldwide · exa.ai
Open questions: Exact founding year and headquarters location from Britannica · Current size and ownership status from Britannica
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-15 04:04:39.266139+00:00