Microsoft Excel Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Release Notes Install KB5002914. Install KB5002904.
Browse 4,344 advisories from this official source. Search by product, CVE, severity, or advisory ID.
Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Release Notes Install KB5002914. Install KB5002904.
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Release Notes Install KB5002914. Install KB5002904.
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Release Notes Install KB5002914. Install KB5002904.
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Release Notes Install KB5002914. Install KB5002904.
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Release Notes Install KB5002914. Install KB5002904.
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Release Notes Install KB5002914. Install KB5002904.
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Release Notes Install KB5002914. Install KB5002904.
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Release Notes Install KB5002914. Install KB5002904.
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Release Notes Install KB5002910. Install KB5002914. Install KB5002904.
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Release Notes Install KB5002914. Install KB5002904.
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Release Notes Install KB5002914. Install KB5002904.
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Release Notes Install KB5002914. Install KB5002904.
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Release Notes Install KB5002914. Install KB5002904.
Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
Release Notes Install KB5002644.
Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Release Notes
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Release Notes
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Release Notes
Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Release Notes
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
Release Notes
Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Release Notes
Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Release Notes
Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Release Notes
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.
Release Notes
Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.
Release Notes
We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.
Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.
Read how SecurityAlert collects and checks threat intelligence.