Access

Vendor:

First CVE: Jan 1, 1999 · Active for 27 years

28
Total CVEs
More Total CVEs than 96% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 73% of tracked products
3.6%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Access over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 1, 1999
27 years ago
Most Recent CVE
Dec 9, 2025
227 days ago

CVE Severity & Scoring

Access28 CVEs
All CVEs352,294 CVEs
MediumHigh
Attack Vector
Local12 (42.9%)
Network2 (7.1%)
Unknown14 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (50.0%)
High0 (0.0%)
Unknown14 (50.0%)
User Interaction
None1 (3.6%)
Unknown14 (50.0%)
Required13 (46.4%)
Privileges Required
Low1 (3.6%)
High0 (0.0%)
None13 (46.4%)
Unknown14 (50.0%)

Top CVEs

Signals from CVEs in this product scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code v
Feb 3, 20078.884YESNO
Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote attackers to execute arbitrary code via long parameters to t
Oct 20, 20037.550NOYES
Microsoft Access 2007 SP3, 2010 SP1 and SP2, and 2013 in Microsoft Office allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a c
Sep 11, 20139.340NONO
The Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 and 2007 SP1 and SP2 do not properly interact with the memory-allocation approach used by Int
Jul 15, 20109.338NONO
The FieldList ActiveX control in the Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 does not properly interact with the memory-access approach u
Jul 15, 20109.336NONO
A remote code execution vulnerability exists when Microsoft Access fails to properly handle objects in memory, aka "Microsoft Access Remote Code Execution Vulnerability." This affe
Jul 11, 20187.833NONO
Microsoft Access 2007 SP3, 2010 SP1 and SP2, and 2013 in Microsoft Office allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a c
Sep 11, 20139.332NONO
Microsoft Access 2007 SP3, 2010 SP1 and SP2, and 2013 in Microsoft Office allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a c
Sep 11, 20139.332NONO
Microsoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 200
Nov 11, 20159.330NONO
The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, ak
May 11, 20007.529NONO

Exploit Exposure

Signals from CVEs in this product scope (28 CVEs).

CISA KEV
1 CVE
3.6% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.6% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (28 CVEs).

Media Mentions

Signals from CVEs in this product scope (28 CVEs).

Top CNAs Publishing CVEs For Access

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9728.817.6%01
2016147.95.1%00
201388.816.5%00
201079.117.5%00
200769.019.8%00
200349.224.5%10
200238.129.0%11
200068.324.0%11