FAIL › dossier
Word
PRODUCT· dossier confidence 95%
Microsoft Word is a widely used word processing product with a documented history of severe security flaws. Its security posture is characterized by recurring high-severity RCE and information disclosure vulnerabilities that are frequently exploited in the wild, including recent zero-day exploits.
PROFILE
CategoryProductWhat they doMicrosoft Word is a word processing application developed by Microsoft.
SECURITY POSTURE
Microsoft Word has a poor security track record with repeated high-severity remote code execution (RCE) and information disclosure vulnerabilities actively exploited in the wild, including recent 0-day exploits bypassing OLE mitigations.
Notable failures
- CVE-2006-2492 RCE
- CVE-2012-2539 RCE/DoS
- CVE-2014-1761 RCE
- CVE-2023-36761 Info Disc
- CVE-2026-21514 0-day RCE
Patterns: Repeated unpatched RCE vulnerabilities; Actively exploited 0-day flaws; Bypass of OLE security mitigations
FAILURE HISTORY · 5
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-06-08 | CVE-2006-2492 | high | A malformed object pointer vulnerability in Microsoft Word allowed remote code execution and was actively exploited in the wild. |
| 2022-03-28 | CVE-2012-2539 | high | A remote code execution flaw in Microsoft Word allowed attackers to execute arbitrary code via crafted RTF data. |
| 2022-02-15 | CVE-2014-1761 | high | A memory corruption flaw in Microsoft Word allowed remote code execution and was actively exploited in the wild. |
| 2023-09-12 | CVE-2023-36761 | high | Microsoft Word's information disclosure vulnerability (CVE-2023-36761) is actively exploited, potentially exposing sensitive data to attackers. |
| 2023-02-14 | CVE-2023-21716 | critical | CVE-2023-21716: Microsoft Word Remote Code Execution Vulnerability |
DOSSIER SOURCES
- IBM - Wikipedia · en.wikipedia.org
- Uber - Wikipedia · en.wikipedia.org
- Word CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
- Microsoft Word Security Vulnerabilities in 2026 - stack.watch · stack.watch
- Microsoft Office Word 0-day Vulnerability Actively Exploited in the Wild · cybersecuritynews.com
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-09 04:53:44.966067+00:00