Office 2019

Vendor:

First CVE: Feb 13, 2024 · Active for 2 years

98
Total CVEs
More Total CVEs than 99% of tracked products
49.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 48% of tracked products
3.1%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Office 2019 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 13, 2024
2 years ago
Most Recent CVE
Jul 14, 2026
14 days ago

CVE Severity & Scoring

Office 201998 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local94 (95.9%)
Network4 (4.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low96 (98.0%)
High2 (2.0%)
Unknown0 (0.0%)
User Interaction
None10 (10.2%)
Unknown0 (0.0%)
Required88 (89.8%)
Privileges Required
Low1 (1.0%)
High0 (0.0%)
None97 (99.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (98 CVEs).

98 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Microsoft Outlook Remote Code Execution Vulnerability
Feb 13, 20249.896YESNO
Microsoft Project Remote Code Execution Vulnerability
Aug 13, 20248.871YESNO
Microsoft Publisher Security Feature Bypass Vulnerability
Sep 10, 20247.365YESNO
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Jun 9, 20268.437NONO
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
Jun 9, 20268.437NONO
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
Jul 14, 20268.435NONO
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Jul 14, 20267.833NONO
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Jul 14, 20267.833NONO
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Jul 14, 20267.833NONO
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Jul 14, 20267.833NONO

Exploit Exposure

Signals from CVEs in this product scope (98 CVEs).

CISA KEV
3 CVEs
3.1% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (98 CVEs).

Media Mentions

Signals from CVEs in this product scope (98 CVEs).

Top CNAs Publishing CVEs For Office 2019

Top CWEs

Versions

No cataloged versions.