PT-2020-1672 · Microsoft · Office

Zhiniang Peng

·

Published

2020-02-11

·

Updated

2021-07-21

·

CVE-2020-0697

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Office (affected versions not specified)
Description The issue is related to insecure privilege management in the OLicenseHeartbeat task of Microsoft Office. An attacker who successfully exploits this could run the task as SYSTEM, potentially allowing them to elevate their privileges. To exploit the issue, an authenticated attacker would need to place a specially crafted file in a specific location, which could lead to arbitrary file corruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00905
CVE-2020-0697

Affected Products

Office