Office Web Apps Server

Vendor:

First CVE: Jan 15, 2014 · Active for 12 years

62
Total CVEs
More Total CVEs than 98% of tracked products
6.9
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
3.2%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Office Web Apps Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 15, 2014
12 years ago
Most Recent CVE
Mar 14, 2023
1,228 days ago

CVE Severity & Scoring

Office Web Apps Server62 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local49 (79.0%)
Network6 (9.7%)
Unknown7 (11.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low55 (88.7%)
High0 (0.0%)
Unknown7 (11.3%)
User Interaction
None3 (4.8%)
Unknown7 (11.3%)
Required52 (83.9%)
Privileges Required
Low5 (8.1%)
High0 (0.0%)
None50 (80.6%)
Unknown7 (11.3%)

Top CVEs

Signals from CVEs in this product scope (62 CVEs).

62 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Serv
Mar 25, 20147.896YESYES
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 201
Oct 13, 20177.892YESNO
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 2016 for Mac, Word Viewer, Word Automation Services on SharePo
Sep 14, 20167.866NOYES
Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memor
Jan 10, 20187.838NONO
A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". Thi
Jun 15, 20178.838NONO
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewe
Jul 13, 20167.838NONO
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Execution Vulnerability.
Jan 8, 20198.837NONO
Microsoft Excel Remote Code Execution Vulnerability
Mar 14, 20237.836NOYES
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewe
Mar 9, 20167.835NONO
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePo
Feb 10, 20167.835NONO

Exploit Exposure

Signals from CVEs in this product scope (62 CVEs).

CISA KEV
2 CVEs
3.2% of CVEs· 97th percentile
Metasploit
1 CVE
1.6% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
4.8% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (62 CVEs).

Media Mentions

Signals from CVEs in this product scope (62 CVEs).

Top CNAs Publishing CVEs For Office Web Apps Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2013607.512.5%23
201078.026.7%10