Office Web Apps

by Microsoft

Take action — actively targeted

Office Web Apps is actively targeted by attackers. A significant proportion of its known vulnerabilities are being exploited.

What to do
  1. Apply all available updates immediately
  2. Review your exposure — is this internet-facing?
  3. Monitor vendor advisories for this product

What Attackers Target

Vulnerabilities with high exploit probability 71.1%
Confirmed actively exploited (CISA) 3.6%
Public exploit code available 2.4%
Based on 83 known vulnerabilities. Percentages show the proportion that are actively dangerous — a low percentage means most vulnerabilities in this product are not being exploited.

Most Dangerous Vulnerabilities

CVE CVSS Exploit Probability Confirmed
CVE-2015-1641 7.8 93.6% Yes
CVE-2014-1761 7.8 92.6% Yes
CVE-2023-21716 9.8 91.4%
CVE-2012-2539 7.8 84.4% Yes
CVE-2016-3282 7.8 54.6%
CVE-2016-3281 7.8 48.4%
CVE-2016-7234 7.8 48.4%
CVE-2020-1447 8.8 46.0%
CVE-2017-0281 7.8 43.3%
CVE-2017-0105 5.5 43.2%
CVE-2016-0183 8.8 40.4%
CVE-2020-0980 7.8 40.2%
CVE-2020-0892 7.8 40.2%
CVE-2020-1446 8.8 39.9%
CVE-2020-1448 8.8 39.3%
CVE-2017-8742 7.8 36.5%
CVE-2018-8539 7.8 36.1%
CVE-2016-0140 7.8 36.0%
CVE-2018-8628 7.8 34.5%
CVE-2016-3279 5.5 34.4%
53
/ 100
high-risk
Active Threat 50/50 · Critical
Exploit Availability 3/50 · Minimal

Score uses Wilson score intervals to account for sample size. Products with few CVEs are scored conservatively.