Product overview
Microsoft Office is tracked by BlackTree as an end-user software application. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
Main capabilities
- User-facing application functions
- Local or managed application deployment
- Vendor-maintained feature and security updates
Typical use
Used by individuals or organizations for the product-specific tasks described by its publisher.
Deployment
Installed on supported endpoints or supplied through a vendor-managed service, depending on the edition.
This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page ↗.
Collected lifecycle data
| Product | Microsoft Office |
|---|
| Release | 2003 |
|---|
| End of Fixed Lifecycle Policy | 9 April 2014 |
|---|
| Date precision | Day |
|---|
Known exploited vulnerabilities
Catalogue updated 11 Sep 2026These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.
Microsoft Office Remote Code Execution
Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.
Microsoft · OfficeRansomware use: Unknown
CISA entry ↗Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability
Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally.
Microsoft · OfficeRansomware use: Unknown
CISA entry ↗Microsoft Office Security Feature Bypass Vulnerability
Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a security feature locally. Some of the impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Microsoft · OfficeRansomware use: Unknown
CISA entry ↗Microsoft Office PowerPoint Code Injection Vulnerability
Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index value that triggers memory corruption.
Microsoft · OfficeRansomware use: Unknown
CISA entry ↗Microsoft Office Excel Remote Code Execution Vulnerability
Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a malicious website. An attacker could leverage this vulnerability by creating a specially crafted Excel file, which, when opened, allowing an attacker to execute remote code on the affected system.
Microsoft · OfficeRansomware use: Unknown
CISA entry ↗Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability
Microsoft Windows Mark of the Web (MOTW) contains a protection mechanism failure vulnerability that allows an attacker to bypass MOTW-based defenses. This can result in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging.
Microsoft · WindowsRansomware use: Unknown
CISA entry ↗Showing the 6 most recently added of 32 product-family matches.
Package vulnerability advisories
OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.
No package advisories have been linked for this product identity.
This is not evidence that the product has no vulnerabilities.
Source evidence
PRIMARYReady
Microsoft lifecycle discovery
{"display_products": ["Office"], "end": "2014-04-09T06:59:59.999Z", "last_modified": "2022-10-26T00:00:00Z", "locale": "en-us", "products": ["office"], "start": "2003-11-17T08:00:00Z", "summary": "Microsoft Office 2003 follows the Fixed Lifecycle Policy.", "title": "Microsoft Office 2003", "url": "/lifecycle/products/microsoft-office-2003"}
Official vendor lifecycle or product-change property. Extracted records require human review.
First collected 25 Aug 2026 · Last collected 12 Sep 2026 · Review state accepted
Open official vendor source ↗