Microsoft vulnerabilities
Showing 651 - 700 of 2.7K CVEs
- CVE-2024-20677 Published Jan 9, 2024
A security vulnerability exists in FBX that could lead to remote code execution. To mitigate this vulnerability, the ability to insert FBX files has been disabled in Word, Excel, PowerPoint and Outlook for Windows and Mac. Versions of Office that had this feature enabled will no longer have access to it. This includes Office 2019, Office 2021, Office LTSC for Mac 2021, and Microsoft 365. As of February 13, 2024, the ability to insert FBX files has also been disabled in 3D Viewer. 3D models in Office documents that were previously inserted from a FBX file will continue to work as expected unless the Link to File option was chosen at insert time. This change is effective as of the January 9, 2024 security update.
- CVE-2024-20656 Published Jan 9, 2024
Visual Studio Elevation of Privilege Vulnerability
- CVE-2024-0057 Published Jan 9, 2024
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
- CVE-2024-0056 Published Jan 9, 2024
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
- CVE-2023-6702 Published Dec 14, 2023
Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-36009 Published Dec 12, 2023
Microsoft Word Information Disclosure Vulnerability
- CVE-2023-6345 Published Nov 29, 2023
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
- CVE-2023-36565 Published Oct 10, 2023
Microsoft Office Graphics Elevation of Privilege Vulnerability
- CVE-2023-5217 Published Sep 28, 2023
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-36761 Published Sep 12, 2023
Microsoft Word Information Disclosure Vulnerability
- CVE-2023-4863 Published Sep 12, 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
- CVE-2023-4762 Published Sep 5, 2023
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-36741 Published Aug 26, 2023
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2023-38158 Published Aug 21, 2023
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
- CVE-2023-36787 Published Aug 21, 2023
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2023-36899 Published Aug 8, 2023
ASP.NET Elevation of Privilege Vulnerability
- CVE-2023-36873 Published Aug 8, 2023
.NET Framework Spoofing Vulnerability
- CVE-2023-38185 Published Aug 8, 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-38182 Published Aug 8, 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-38181 Published Aug 8, 2023
Microsoft Exchange Server Spoofing Vulnerability
- CVE-2023-38169 Published Aug 8, 2023
Microsoft SQL OLE DB Remote Code Execution Vulnerability
- CVE-2023-36897 Published Aug 8, 2023
Visual Studio Tools for Office Runtime Spoofing Vulnerability
- CVE-2023-36896 Published Aug 8, 2023
Microsoft Excel Remote Code Execution Vulnerability
- CVE-2023-36895 Published Aug 8, 2023
Microsoft Outlook Remote Code Execution Vulnerability
- CVE-2023-36893 Published Aug 8, 2023
Microsoft Outlook Spoofing Vulnerability
- CVE-2023-36866 Published Aug 8, 2023
Microsoft Office Visio Remote Code Execution Vulnerability
- CVE-2023-36865 Published Aug 8, 2023
Microsoft Office Visio Remote Code Execution Vulnerability
- CVE-2023-35388 Published Aug 8, 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-35372 Published Aug 8, 2023
Microsoft Office Visio Remote Code Execution Vulnerability
- CVE-2023-35371 Published Aug 8, 2023
Microsoft Office Remote Code Execution Vulnerability
- CVE-2023-35368 Published Aug 8, 2023
Microsoft Exchange Remote Code Execution Vulnerability
- CVE-2023-29330 Published Aug 8, 2023
Microsoft Teams Remote Code Execution Vulnerability
- CVE-2023-29328 Published Aug 8, 2023
Microsoft Teams Remote Code Execution Vulnerability
- CVE-2023-21709 Published Aug 8, 2023
Microsoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2023-38157 Published Aug 7, 2023
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
- CVE-2023-35311 Published Jul 11, 2023
Microsoft Outlook Security Feature Bypass Vulnerability
- CVE-2023-33162 Published Jul 11, 2023
Microsoft Excel Information Disclosure Vulnerability
- CVE-2023-33161 Published Jul 11, 2023
Microsoft Excel Remote Code Execution Vulnerability
- CVE-2023-33158 Published Jul 11, 2023
Microsoft Excel Remote Code Execution Vulnerability
- CVE-2023-33153 Published Jul 11, 2023
Microsoft Outlook Remote Code Execution Vulnerability
- CVE-2023-33152 Published Jul 11, 2023
Microsoft ActiveX Remote Code Execution Vulnerability
- CVE-2023-33151 Published Jul 11, 2023
Microsoft Outlook Spoofing Vulnerability
- CVE-2023-33150 Published Jul 11, 2023
Microsoft Office Security Feature Bypass Vulnerability
- CVE-2023-33149 Published Jul 11, 2023
Microsoft Office Graphics Remote Code Execution Vulnerability
- CVE-2023-33148 Published Jul 11, 2023
Microsoft Office Elevation of Privilege Vulnerability
- CVE-2023-32029 Published Jun 14, 2023
Microsoft Excel Remote Code Execution Vulnerability
- CVE-2023-29357 Published Jun 14, 2023
Microsoft SharePoint Server Elevation of Privilege Vulnerability
- CVE-2023-29335 Published May 9, 2023
Microsoft Word Security Feature Bypass Vulnerability
- CVE-2023-29333 Published May 9, 2023
Microsoft Access Denial of Service Vulnerability
- CVE-2023-24955 Published May 9, 2023
Microsoft SharePoint Server Remote Code Execution Vulnerability
A security vulnerability exists in FBX that could lead to remote code execution. To mitigate this vulnerability, the ability to insert FBX files has been disabled in Word, Excel, PowerPoint and Outlook for Windows and Mac. Versions of Office that had this feature enabled will no longer have access to it. This includes Office 2019, Office 2021, Office LTSC for Mac 2021, and Microsoft 365. As of February 13, 2024, the ability to insert FBX files has also been disabled in 3D Viewer. 3D models in Office documents that were previously inserted from a FBX file will continue to work as expected unless the Link to File option was chosen at insert time. This change is effective as of the January 9, 2024 security update.
high 7.8
Visual Studio Elevation of Privilege Vulnerability
high 7.8
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
critical 9.1
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
high 8.7
Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
high 8.8
Microsoft Word Information Disclosure Vulnerability
medium 5.5
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
critical 9.6
Microsoft Office Graphics Elevation of Privilege Vulnerability
high 7.0
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
high 8.8
Microsoft Word Information Disclosure Vulnerability
medium 6.5
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
high 8.8
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
high 8.8
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high 8.3
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
low 3.1
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high 8.8
ASP.NET Elevation of Privilege Vulnerability
high 8.8
.NET Framework Spoofing Vulnerability
high 7.4
Microsoft Exchange Server Remote Code Execution Vulnerability
high 8.8
Microsoft Exchange Server Remote Code Execution Vulnerability
high 8.0
Microsoft Exchange Server Spoofing Vulnerability
high 8.8
Microsoft SQL OLE DB Remote Code Execution Vulnerability
high 8.8
Visual Studio Tools for Office Runtime Spoofing Vulnerability
high 8.1
Microsoft Excel Remote Code Execution Vulnerability
high 7.8
Microsoft Outlook Remote Code Execution Vulnerability
high 7.8
Microsoft Outlook Spoofing Vulnerability
medium 6.5
Microsoft Office Visio Remote Code Execution Vulnerability
high 7.8
Microsoft Office Visio Remote Code Execution Vulnerability
high 7.8
Microsoft Exchange Server Remote Code Execution Vulnerability
high 8.0
Microsoft Office Visio Remote Code Execution Vulnerability
high 7.8
Microsoft Office Remote Code Execution Vulnerability
high 7.8
Microsoft Exchange Remote Code Execution Vulnerability
high 8.8
Microsoft Teams Remote Code Execution Vulnerability
high 8.8
Microsoft Teams Remote Code Execution Vulnerability
high 8.8
Microsoft Exchange Server Elevation of Privilege Vulnerability
critical 9.8
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
medium 6.5
Microsoft Outlook Security Feature Bypass Vulnerability
high 8.8
Microsoft Excel Information Disclosure Vulnerability
medium 5.5
Microsoft Excel Remote Code Execution Vulnerability
high 7.8
Microsoft Excel Remote Code Execution Vulnerability
high 7.8
Microsoft Outlook Remote Code Execution Vulnerability
medium 6.8
Microsoft ActiveX Remote Code Execution Vulnerability
high 7.0
Microsoft Outlook Spoofing Vulnerability
medium 6.5
Microsoft Office Security Feature Bypass Vulnerability
critical 9.6
Microsoft Office Graphics Remote Code Execution Vulnerability
high 7.8
Microsoft Office Elevation of Privilege Vulnerability
high 7.8
Microsoft Excel Remote Code Execution Vulnerability
high 7.8
Microsoft SharePoint Server Elevation of Privilege Vulnerability
critical 9.8
Microsoft Word Security Feature Bypass Vulnerability
high 7.5
Microsoft Access Denial of Service Vulnerability
low 3.3
Microsoft SharePoint Server Remote Code Execution Vulnerability
high 7.2