Office Web Apps

Vendor:

First CVE: Oct 13, 2010 · Active for 15 years

106
Total CVEs
More Total CVEs than 99% of tracked products
7.6
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 59% of tracked products
2.8%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Office Web Apps over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 13, 2010
15 years ago
Most Recent CVE
Feb 14, 2023
1,256 days ago

CVE Severity & Scoring

Office Web Apps106 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local65 (61.3%)
Network18 (17.0%)
Unknown23 (21.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low82 (77.4%)
High1 (0.9%)
Unknown23 (21.7%)
User Interaction
None3 (2.8%)
Unknown23 (21.7%)
Required80 (75.5%)
Privileges Required
Low4 (3.8%)
High0 (0.0%)
None79 (74.5%)
Unknown23 (21.7%)

Top CVEs

Signals from CVEs in this product scope (106 CVEs).

106 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Serv
Mar 25, 20147.896YESYES
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint S
Apr 14, 20157.894YESNO
Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrar
Dec 12, 20127.886YESNO
Microsoft Word Remote Code Execution Vulnerability
Feb 14, 20239.877NONO
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 2016 for Mac, Word Viewer, Word Automation Services on SharePo
Sep 14, 20167.866NOYES
Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP
Sep 15, 20114.044NOYES
Stack-based buffer overflow in Microsoft Word 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Compatibility Pac
Oct 13, 20109.341NONO
Use-after-free vulnerability in Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; Word Automation Services on Microsoft S
Oct 9, 20129.340NONO
Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2
Apr 14, 20159.339NONO
Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memor
Jan 10, 20187.838NONO

Exploit Exposure

Signals from CVEs in this product scope (106 CVEs).

CISA KEV
3 CVEs
2.8% of CVEs· 96th percentile
Metasploit
1 CVE
0.9% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
2.8% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (106 CVEs).

Media Mentions

Signals from CVEs in this product scope (106 CVEs).

Top CNAs Publishing CVEs For Office Web Apps

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2013527.511.7%10
2010757.420.6%33