Microsoft Office Long Term Servicing Channel — known CVE vulnerabilities
Every CVE whose affected-product data names Microsoft Office Long Term Servicing Channel, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVE-2025-60724 — CVSS 9.8 (critical): Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
CVE-2026-26113 — CVSS 8.4 (high): Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40363 — CVSS 8.4 (high): Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-47167 — CVSS 8.4 (high): Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-47162 — CVSS 8.4 (high): Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40367 — CVSS 8.4 (high): Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code…
CVE-2026-26110 — CVSS 8.4 (high): Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-54910 — CVSS 8.4 (high): Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-53733 — CVSS 8.4 (high): Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-33115 — CVSS 8.4 (high): Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40366 — CVSS 8.4 (high): Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code…
CVE-2026-20944 — CVSS 8.4 (high): Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-49697 — CVSS 8.4 (high): Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-33114 — CVSS 8.4 (high): Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-62554 — CVSS 8.4 (high): Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-59236 — CVSS 8.4 (high): Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-49696 — CVSS 8.4 (high): Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-47957 — CVSS 8.4 (high): Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40364 — CVSS 8.4 (high): Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code…
CVE-2024-20677 — CVSS 7.8 (high): A security vulnerability exists in FBX that could lead to remote code execution. To mitigate this vulnerability, the ability to insert FBX…
CVE-2025-47175 — CVSS 7.8 (high): Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2025-47176 — CVSS 7.8 (high): '.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.
CVE-2025-47994 — CVSS 7.8 (high): Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.
CVE-2025-49698 — CVSS 7.8 (high): Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-49700 — CVSS 7.8 (high): Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-49702 — CVSS 7.8 (high): Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-49703 — CVSS 7.8 (high): Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-49705 — CVSS 7.8 (high): Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2025-49711 — CVSS 7.8 (high): Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-53730 — CVSS 7.8 (high): Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.
CVE-2025-53734 — CVSS 7.8 (high): Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.
CVE-2025-53735 — CVSS 7.8 (high): Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-53737 — CVSS 7.8 (high): Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-53738 — CVSS 7.8 (high): Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-53739 — CVSS 7.8 (high): Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code…
CVE-2025-53741 — CVSS 7.8 (high): Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-53759 — CVSS 7.8 (high): Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-53761 — CVSS 7.8 (high): Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2025-54896 — CVSS 7.8 (high): Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-54898 — CVSS 7.8 (high): Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-54899 — CVSS 7.8 (high): Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-54900 — CVSS 7.8 (high): Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-54902 — CVSS 7.8 (high): Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-54903 — CVSS 7.8 (high): Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-54904 — CVSS 7.8 (high): Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-54906 — CVSS 7.8 (high): Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-54907 — CVSS 7.8 (high): Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code locally.
CVE-2025-54908 — CVSS 7.8 (high): Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2025-59222 — CVSS 7.8 (high): Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-59223 — CVSS 7.8 (high): Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-59224 — CVSS 7.8 (high): Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-59225 — CVSS 7.8 (high): Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-59226 — CVSS 7.8 (high): Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.
CVE-2025-59231 — CVSS 7.8 (high): Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code…
CVE-2025-59233 — CVSS 7.8 (high): Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code…
CVE-2025-62552 — CVSS 7.8 (high): Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2025-62553 — CVSS 7.8 (high): Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62556 — CVSS 7.8 (high): Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62558 — CVSS 7.8 (high): Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-62559 — CVSS 7.8 (high): Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-62560 — CVSS 7.8 (high): Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62561 — CVSS 7.8 (high): Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62562 — CVSS 7.8 (high): Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.
CVE-2025-62563 — CVSS 7.8 (high): Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62564 — CVSS 7.8 (high): Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-20946 — CVSS 7.8 (high): Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-20948 — CVSS 7.8 (high): Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-20949 — CVSS 7.8 (high): Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-20950 — CVSS 7.8 (high): Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-20955 — CVSS 7.8 (high): Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-20956 — CVSS 7.8 (high): Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-20957 — CVSS 7.8 (high): Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-21259 — CVSS 7.8 (high): Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally.