Skip to content
COOEY

FAIL › dossier

Office

PRODUCT

· dossier confidence 20%

Microsoft Office is a dominant productivity suite but has a documented history of critical and high-severity remote code execution vulnerabilities, requiring vigilant patch management to prevent exploitation. Recent events show active exploitation of zero-day flaws in identity and collaboration services, highlighting persistent security gaps despite large-scale patching efforts.

PROFILE
CategorySoftwareWhat they doMicrosoft Corporation develops and sells productivity software, operating systems, and cloud computing services, with Microsoft Office being its flagship productivity suite. Websitehttps://www.microsoft.com ↗
SECURITY POSTURE

Microsoft maintains a proactive patching program but suffers from a high volume of critical and high-severity remote code execution (RCE) vulnerabilities across its Office suite, often requiring urgent patching cycles to mitigate exploitation risks.

Notable failures
  • CVE-2021-38646 (critical RCE in Office Access)
  • CVE-2017-11882 (critical RCE in Office)
  • CVE-2026-56155 (actively exploited AD FS zero-day)
Patterns: repeated unpatched edge-device RCEs; memory corruption leading to RCE; security feature bypasses via untrusted inputs
FAILURE HISTORY · 31
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2017-11882 critical A Microsoft Office memory corruption vulnerability allowed for remote code execution and was actively exploited, likely contributing to ransomware attacks.
2026-04-14 CVE-2009-0238 high Microsoft Office Excel contains a remote code execution vulnerability that allows attackers to take complete control of a system by opening a specially crafted file.
2022-03-03 CVE-2012-1856 high A 12-year-old unpatched Microsoft Office ActiveX vulnerability in MSCOMCTL.OCX allows remote attackers to execute arbitrary code via crafted documents or web pages.
2022-03-03 CVE-2010-3333 high A stack-based buffer overflow in Microsoft Office's RTF parser allowed remote code execution, and it was actively exploited in the wild.
2022-06-08 CVE-2009-0557 high A malformed Excel file could trigger remote code execution in Microsoft Office via an object record corruption flaw.
2022-03-03 CVE-2016-7193 high A memory corruption flaw in Microsoft Office allowed remote code execution and was actively exploited in the wild.
2022-02-25 CVE-2017-8570 high Microsoft Office contained an unpatched remote code execution vulnerability that was actively exploited in the wild.
2021-11-03 CVE-2018-0802 high A memory corruption flaw in Microsoft Office allowed remote code execution when chained with another vulnerability, and was actively exploited in the wild.
2022-03-28 CVE-2015-1770 high A remote code execution vulnerability in Microsoft Office allowed attackers to execute arbitrary code via a crafted document.
2022-03-03 CVE-2017-0261 high Microsoft Office contained a use-after-free vulnerability allowing remote code execution that was actively exploited in the wild.
2022-03-03 CVE-2015-2545 high A malformed EPS file in Microsoft Office allowed remote attackers to execute arbitrary code, and the vulnerability was actively exploited in the wild.
2022-03-03 CVE-2017-11826 high Microsoft Office had a remote code execution vulnerability that was actively exploited in the wild.
2022-02-10 CVE-2017-0262 high Microsoft Office contained a remote code execution vulnerability that was actively exploited in the wild.
2021-11-17 CVE-2021-42292 high A local user can bypass Excel security features to execute arbitrary code.
2021-11-03 CVE-2018-0798 high Microsoft Office memory corruption flaw allows remote code execution and is actively exploited in the wild.
2021-11-03 CVE-2021-27059 high Microsoft Office contained an unpatched remote code execution vulnerability that was actively exploited in the wild.
2021-11-03 CVE-2016-3235 high Microsoft Office OLE DLL side loading vulnerability allowed remote code execution by improperly validating input before loading libraries.
2021-11-03 CVE-2015-1641 high A memory corruption flaw in Microsoft Office allowed remote code execution when processing rich text format files.
2026-02-10 CVE-2026-21514 high Authorized attacker could elevate privileges in Microsoft Office Word due to reliance on untrusted inputs
2026-01-26 CVE-2026-21509 high Microsoft Office flaw exploited, users advised to transition to supported versions.
2026-01-07 CVE-2009-0556 high Microsoft Office PowerPoint allowed remote code execution through a vulnerability in its software.
2025-08-12 CVE-2007-0671 high Microsoft Excel allowed remote code execution through malicious files.
2023-03-14 CVE-2023-23397 high Microsoft Office Outlook allows NTLM Relay attacks
2023-02-14 CVE-2023-21715 high Microsoft Publisher flaw exploited in wild
2022-06-08 CVE-2009-0563 high A 2009 Microsoft Office buffer overflow flaw allowed remote attackers to execute code via crafted Word documents.
2022-03-28 CVE-2021-38646 critical A Microsoft Office vulnerability allowed authenticated users to inject SQL and potentially execute arbitrary code remotely, actively exploited in ransomware attacks.
2022-03-03 CVE-2015-1642 high A memory corruption flaw in Microsoft Office allowed remote attackers to execute arbitrary code via a crafted document.
2021-11-03 CVE-2017-11774 high A memory handling flaw in Microsoft Outlook allowed attackers to bypass security features and execute arbitrary commands.
2022-06-08 CVE-2013-1331 high A Microsoft Office buffer overflow vulnerability allows remote code execution via crafted PNG files, and is currently being exploited in the wild.
2023-02-14 CVE-2023-21716 critical CVE-2023-21716: Microsoft Word Remote Code Execution Vulnerability
2020-05-21 CVE-2020-0901 critical CVE-2020-0901: A remote code execution vulnerability exists in Microsoft Excel software when th
Open questions: Exact founding year and headquarters location from Britannica · Current size and ownership status from Britannica
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-15 04:04:39.266139+00:00