Multiple Excel vulnerabilities on different records type parsing and formats conversion. Multiple Microsoft Word code execution vulnerabilities. Memory corruptions in different Office products.
It's possible to include scripting object which fill be activated in case user reply or forward e-mail message.
Host method of spreadsheet object allows creation and execution of arbitrary files.