Office Compatibility Pack

by Microsoft

Take action — actively targeted

Office Compatibility Pack is actively targeted by attackers. A significant proportion of its known vulnerabilities are being exploited.

What to do
  1. Apply all available updates immediately
  2. Review your exposure — is this internet-facing?
  3. Monitor vendor advisories for this product

What Attackers Target

Vulnerabilities with high exploit probability 97.1%
Confirmed actively exploited (CISA) 11.5%
Public exploit code available 2.9%
Based on 104 known vulnerabilities. Percentages show the proportion that are actively dangerous — a low percentage means most vulnerabilities in this product are not being exploited.

Most Dangerous Vulnerabilities

CVE CVSS Exploit Probability Confirmed
CVE-2018-0802 7.8 94.1% Yes
CVE-2018-0798 8.8 94.1% Yes
CVE-2015-1641 7.8 93.6% Yes
CVE-2013-3906 7.8 92.6% Yes
CVE-2014-1761 7.8 92.6% Yes
CVE-2017-11826 7.8 90.8% Yes
CVE-2016-7262 7.8 87.1% Yes
CVE-2009-0557 7.8 86.4% Yes
CVE-2012-2539 7.8 84.4% Yes
CVE-2009-0563 7.8 79.9% Yes
CVE-2015-2424 8.8 76.5% Yes
CVE-2010-0258 7.8 71.4%
CVE-2016-7193 7.8 71.2% Yes
CVE-2013-0006 8.8 68.3%
CVE-2016-3282 7.8 54.6%
CVE-2016-0134 7.8 48.5%
CVE-2016-7234 7.8 48.4%
CVE-2009-2502 8.1 47.5%
CVE-2017-0194 5.5 44.2%
CVE-2017-0105 5.5 43.2%
62
/ 100
high-risk
Active Threat 50/50 · Critical
Exploit Availability 12/50 · Low

Score uses Wilson score intervals to account for sample size. Products with few CVEs are scored conservatively.