Office 2016

Vendor:

First CVE: Feb 13, 2024 · Active for 2 years

38
Total CVEs
More Total CVEs than 97% of tracked products
19.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
2.6%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Office 2016 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 13, 2024
2 years ago
Most Recent CVE
Jul 14, 2026
11 days ago

CVE Severity & Scoring

Office 201638 CVEs
All CVEs352,427 CVEs
LowMediumHighCritical
Attack Vector
Local37 (97.4%)
Network1 (2.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low38 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (21.1%)
Unknown0 (0.0%)
Required30 (78.9%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None38 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (38 CVEs).

38 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Microsoft Outlook Remote Code Execution Vulnerability
Feb 13, 20249.896YESNO
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
Jun 9, 20268.437NONO
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
Jul 14, 20268.435NONO
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Jul 14, 20267.833NONO
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Jul 14, 20267.833NONO
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Jun 9, 20268.433NONO
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Jul 14, 20267.832NONO
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Jul 14, 20267.832NONO
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Jul 14, 20267.832NONO
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Jul 14, 20267.832NONO

Exploit Exposure

Signals from CVEs in this product scope (38 CVEs).

CISA KEV
1 CVE
2.6% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (38 CVEs).

Media Mentions

Signals from CVEs in this product scope (38 CVEs).

Top CNAs Publishing CVEs For Office 2016

Top CWEs

Versions

No cataloged versions.