Access
Vendor:
First CVE: Jan 1, 1999 · Active for 27 years
28
Total CVEs
More Total CVEs than 96% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 73% of tracked products
3.6%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Access over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 1, 1999
27 years ago
Most Recent CVE
Dec 9, 2025
227 days ago
CVE Severity & Scoring
Access28 CVEs
96%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local12 (42.9%)
Network2 (7.1%)
Unknown14 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (50.0%)
High0 (0.0%)
Unknown14 (50.0%)
User Interaction
None1 (3.6%)
Unknown14 (50.0%)
Required13 (46.4%)
Privileges Required
Low1 (3.6%)
High0 (0.0%)
None13 (46.4%)
Unknown14 (50.0%)
Top CVEs
Signals from CVEs in this product scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-0671HIGH Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code v | Feb 3, 2007 | 8.8 | 84 | YES | NO |
CVE-2003-0665HIGH Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote attackers to execute arbitrary code via long parameters to t | Oct 20, 2003 | 7.5 | 50 | NO | YES |
CVE-2013-3157HIGH Microsoft Access 2007 SP3, 2010 SP1 and SP2, and 2013 in Microsoft Office allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a c | Sep 11, 2013 | 9.3 | 40 | NO | NO |
CVE-2010-0814HIGH The Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 and 2007 SP1 and SP2 do not properly interact with the memory-allocation approach used by Int | Jul 15, 2010 | 9.3 | 38 | NO | NO |
CVE-2010-1881HIGH The FieldList ActiveX control in the Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 does not properly interact with the memory-access approach u | Jul 15, 2010 | 9.3 | 36 | NO | NO |
CVE-2018-8312HIGH A remote code execution vulnerability exists when Microsoft Access fails to properly handle objects in memory, aka "Microsoft Access Remote Code Execution Vulnerability." This affe | Jul 11, 2018 | 7.8 | 33 | NO | NO |
CVE-2013-3156HIGH Microsoft Access 2007 SP3, 2010 SP1 and SP2, and 2013 in Microsoft Office allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a c | Sep 11, 2013 | 9.3 | 32 | NO | NO |
CVE-2013-3155HIGH Microsoft Access 2007 SP3, 2010 SP1 and SP2, and 2013 in Microsoft Office allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a c | Sep 11, 2013 | 9.3 | 32 | NO | NO |
CVE-2015-2503HIGH Microsoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 200 | Nov 11, 2015 | 9.3 | 30 | NO | NO |
CVE-2000-0419HIGH The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, ak | May 11, 2000 | 7.5 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (28 CVEs).
CISA KEV
1 CVE
3.6% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.6% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (28 CVEs).
Media Mentions
Signals from CVEs in this product scope (28 CVEs).
Top CNAs Publishing CVEs For Access
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 97 | 2 | 8.8 | 17.6% | 0 | 1 |
| 2016 | 14 | 7.9 | 5.1% | 0 | 0 |
| 2013 | 8 | 8.8 | 16.5% | 0 | 0 |
| 2010 | 7 | 9.1 | 17.5% | 0 | 0 |
| 2007 | 6 | 9.0 | 19.8% | 0 | 0 |
| 2003 | 4 | 9.2 | 24.5% | 1 | 0 |
| 2002 | 3 | 8.1 | 29.0% | 1 | 1 |
| 2000 | 6 | 8.3 | 24.0% | 1 | 1 |