Office For Mac
Vendor:
First CVE: Dec 20, 2016 · Active for 9 years
10
Total CVEs
More Total CVEs than 88% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Office For Mac over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 20, 2016
9 years ago
Most Recent CVE
Sep 13, 2018
2,872 days ago
CVE Severity & Scoring
Office For Mac10 CVEs
20%
80%
All CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local7 (70.0%)
Network3 (30.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (10.0%)
Unknown0 (0.0%)
Required9 (90.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None9 (90.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-8176HIGH A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly validate XML content, aka "Microsoft PowerPoint Remote Code Execut | May 23, 2018 | 8.8 | 39 | NO | NO |
CVE-2018-8332HIGH A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerabi | Sep 13, 2018 | 8.8 | 36 | NO | NO |
CVE-2018-8162HIGH A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vu | May 9, 2018 | 7.8 | 36 | NO | NO |
CVE-2018-8147HIGH A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vu | May 9, 2018 | 7.8 | 36 | NO | NO |
CVE-2017-11825HIGH Microsoft Office 2016 Click-to-Run (C2R) and Microsoft Office 2016 for Mac allow an attacker to use a specially crafted file to perform actions in the security context of the curre | Oct 13, 2017 | 7.8 | 36 | NO | NO |
CVE-2018-8148HIGH A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vu | May 9, 2018 | 7.8 | 35 | NO | NO |
CVE-2016-7276HIGH Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office for Mac 2011, and Office 2016 for Mac allow remote attackers to obtain sensitive information from process memory | Dec 20, 2016 | 7.1 | 29 | NO | NO |
CVE-2018-8412HIGH An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing them, aka "Microsoft (MAU) Offi | Aug 15, 2018 | 7.8 | 26 | NO | NO |
CVE-2016-7257MEDIUM The GDI component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office for Mac 2011, and Office 2016 for Mac allows remote attackers to obtain | Dec 20, 2016 | 6.5 | 26 | NO | NO |
CVE-2018-8429MEDIUM An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." Thi | Sep 13, 2018 | 5.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Office For Mac
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2016 | 10 | 7.6 | 19.8% | 0 | 0 |
| 2011 | 2 | 6.8 | 23.8% | 0 | 0 |