Microsoft Office Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
Release Notes Install KB5002916.
Browse 4,344 advisories from this official source. Search by product, CVE, severity, or advisory ID.
Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
Release Notes Install KB5002916.
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Install KB5122771. Install KB5122770. Install KB5122768. Install KB5122769.
Out-of-bounds read in SQL Server allows an authorized attacker to execute code over a network.
Install KB5122773. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122768. Install KB5122769.
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Install KB5122769. Install KB5122768. Install KB5122775. Install KB5122773. Install KB5122774. Install KB5122771. Install KB5122770. Install KB5122772.
Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.
Install KB5122773. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122769. Install KB5122768.
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
Install KB5123300. Install KB5123287. Install KB5123301.
Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
Release Notes
Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.
Release Notes
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.
Update Information
Mariner
Release Notes CBL-Mariner Releases
Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.
Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.
Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5123099. Install KB5123065. Install KB5123066.
Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.
Install KB5124008.
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Release Notes Install KB5002904. Install KB5002914.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.
Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.
Release Notes
We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.
Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.
Read how SecurityAlert collects and checks threat intelligence.