threat
engine
.sh
Back
·
··:··
Home
/
Product
/
microsoft access
Product
microsoft access
36 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2025-62552
all versions
Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.
7.8
HIGH
CVE-2025-59235
all versions
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
7.1
HIGH
CVE-2025-59232
all versions
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
7.1
HIGH
CVE-2025-26642
all versions
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
7.8
HIGH
CVE-2025-26630
all versions
Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally.
7.8
HIGH
CVE-2025-21395
all versions
Microsoft Access Remote Code Execution Vulnerability
7.8
HIGH
CVE-2025-21366
all versions
Microsoft Access Remote Code Execution Vulnerability
7.8
HIGH
CVE-2025-21186
all versions
Microsoft Access Remote Code Execution Vulnerability
7.8
HIGH
CVE-2024-49142
all versions
Microsoft Access Remote Code Execution Vulnerability
7.8
HIGH
CVE-2022-31701
all versions
VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity
5.3
MEDIUM
CVE-2022-31700
all versions
VMware Workspace ONE Access and Identity Manager contain an authenticated remote code execution vulnerability. VMware has evaluate
7.2
HIGH
CVE-2020-1582
all versions
A remote code execution vulnerability exists in Microsoft Access software when the software fails to properly handle objects in me
7.8
HIGH
CVE-2020-0760
all versions
A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Offic
8.8
HIGH
CVE-2019-18780
<= 7.4.2
An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote
9.8
CRITICAL
CVE-2019-11899
<= 3.7
An unauthenticated attacker can achieve unauthorized access to sensitive data by exploiting Windows SMB protocol on a client insta
7.5
HIGH
CVE-2019-11898
< 3.8
Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The service tool i
9.9
CRITICAL
CVE-2018-8312
all versions
A remote code execution vulnerability exists when Microsoft Access fails to properly handle objects in memory, aka "Microsoft Acce
7.8
HIGH
CVE-2018-0903
all versions
Microsoft Access 2010 SP2, Microsoft Access 2013 SP1, Microsoft Access 2016, and Microsoft Office 2016 Click-to-Run allow a remote
7.8
HIGH
CVE-2017-6406
<= 7.2.1
An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Arbitrary privileged command execu
8.8
HIGH
CVE-2017-6400
<= 7.2.1
An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Privileged command execution on Ne
8.8
HIGH
CVE-2017-6399
<= 7.2.1
An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Privileged remote command executio
8.8
HIGH
CVE-2015-2503
all versions
Microsoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2
CVE-2013-3157
all versions
Microsoft Access 2007 SP3, 2010 SP1 and SP2, and 2013 in Microsoft Office allows remote attackers to execute arbitrary code or cau
CVE-2013-3156
all versions
Microsoft Access 2007 SP3, 2010 SP1 and SP2, and 2013 in Microsoft Office allows remote attackers to execute arbitrary code or cau
CVE-2013-3155
all versions
Microsoft Access 2007 SP3, 2010 SP1 and SP2, and 2013 in Microsoft Office allows remote attackers to execute arbitrary code or cau
CVE-2010-1881
all versions
The FieldList ActiveX control in the Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 does not p
CVE-2010-0814
all versions
The Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 and 2007 SP1 and SP2 do not properly intera
CVE-2008-3068
all versions
Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Rev
CVE-2008-1200
all versions
Unspecified vulnerability in Microsoft Access allows remote user-assisted attackers to execute arbitrary code via a crafted .MDB f
CVE-2007-6357
all versions
Stack-based buffer overflow in Microsoft Office Access allows remote, user-assisted attackers to execute arbitrary code via a craf
CVE-2007-0671
all versions
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote u
8.8
HIGH
CVE-2006-3877
all versions
Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X fo
CVE-2003-0665
all versions
Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote attackers
CVE-2000-0788
all versions
The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database,
CVE-2000-0419
all versions
The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activi
CVE-1999-0364
all versions
Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin