Skip to content
COOEY

FAIL › dossier

Word

PRODUCT

· dossier confidence 95%

Microsoft Word is a widely used word processing product with a documented history of severe security flaws. Its security posture is characterized by recurring high-severity RCE and information disclosure vulnerabilities that are frequently exploited in the wild, including recent zero-day exploits.

PROFILE
CategoryProductWhat they doMicrosoft Word is a word processing application developed by Microsoft.
SECURITY POSTURE

Microsoft Word has a poor security track record with repeated high-severity remote code execution (RCE) and information disclosure vulnerabilities actively exploited in the wild, including recent 0-day exploits bypassing OLE mitigations.

Notable failures
  • CVE-2006-2492 RCE
  • CVE-2012-2539 RCE/DoS
  • CVE-2014-1761 RCE
  • CVE-2023-36761 Info Disc
  • CVE-2026-21514 0-day RCE
Patterns: Repeated unpatched RCE vulnerabilities; Actively exploited 0-day flaws; Bypass of OLE security mitigations
FAILURE HISTORY · 5
DATEEVENTSEVSUMMARY
2022-06-08 CVE-2006-2492 high A malformed object pointer vulnerability in Microsoft Word allowed remote code execution and was actively exploited in the wild.
2022-03-28 CVE-2012-2539 high A remote code execution flaw in Microsoft Word allowed attackers to execute arbitrary code via crafted RTF data.
2022-02-15 CVE-2014-1761 high A memory corruption flaw in Microsoft Word allowed remote code execution and was actively exploited in the wild.
2023-09-12 CVE-2023-36761 high Microsoft Word's information disclosure vulnerability (CVE-2023-36761) is actively exploited, potentially exposing sensitive data to attackers.
2023-02-14 CVE-2023-21716 critical CVE-2023-21716: Microsoft Word Remote Code Execution Vulnerability
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-09 04:53:44.966067+00:00