Exposição de Microsoft Word

Editors
15
score de exposição
10.802
sites usam
0
em exploração
0
críticos
Análise Vexday

O histórico de vulnerabilidades catalogadas para o Microsoft Word soma 22 CVEs, com taxa de exploração ativa abaixo da média geral do catálogo CISA KEV — nenhuma entrada confirmada ativamente explorada no momento. A ausência de CVEs críticas e de novos registros nos últimos 90 dias sugere um período de relativa estabilidade no perfil de risco recente dessa tecnologia. Ainda assim, merece atenção o CVE-2018-0792, que concentra o maior escore EPSS observado no conjunto (0,2834), indicando probabilidade não desprezível de exploração, mesmo sendo uma vulnerabilidade mais antiga. Equipes responsáveis por ambientes com Word devem verificar se esse CVE específico foi devidamente corrigido, já que scores EPSS elevados em vulnerabilidades legadas frequentemente refletem disponibilidade de código de exploração público.

CVEs

22 resultados
CVE-2018-0792Microsoft Word 2016 in Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka EPSS 25.6%CVE-2018-8430A remote code execution vulnerability exists in Microsoft Word if a user opens a specially crafted PDF file, aka "Word PDF Remote Code ExecuEPSS 20.0%CVE-2019-0585A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft WEPSS 19.8%CVE-2018-8161A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka EPSS 19.5%CVE-2018-0794Microsoft Word in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code executEPSS 18.7%CVE-2018-8504A remote code execution vulnerability exists in Microsoft Word software when the software fails to properly handle objects in Protected ViewEPSS 18.4%CVE-2018-8573A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft WEPSS 17.4%CVE-2019-0953A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft WEPSS 12.1%CVE-2020-0980A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft WEPSS 11.8%CVE-2020-0892A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft WEPSS 11.8%CVE-2020-1446A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft WEPSS 11.2%CVE-2020-1447A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft WEPSS 10.6%CVE-2020-1448A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft WEPSS 10.0%CVE-2020-0850A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft WEPSS 8.8%CVE-2020-0760A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote CEPSS 8.8%CVE-2018-0950An information disclosure vulnerability exists when Office renders Rich Text Format (RTF) email messages containing OLE objects when a messaEPSS 7.6%CVE-2020-1342An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, whEPSS 6.4%CVE-2020-1445An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka 'Microsoft Office EPSS 6.1%CVE-2019-0561An information disclosure vulnerability exists when Microsoft Word macro buttons are used improperly, aka "Microsoft Word Information DiscloEPSS 5.8%CVE-2018-8310A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails, aka "EPSS 5.5%