PT-2020-2253 · Microsoft · Office+1

Published

2020-04-14

·

Updated

2021-07-21

·

CVE-2020-0991

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Office (affected versions not specified) Microsoft Office 365 (affected versions not specified)
Description A remote code execution issue exists in Microsoft Office software due to improper handling of objects in memory. This allows a remote attacker to execute arbitrary code. If the current user has administrative rights, the attacker could gain control of the affected system, install programs, view, change, or delete data, or create new accounts with full user rights. The exploitation requires a user to open a specially crafted file with an affected version of Microsoft Office.
Recommendations For Microsoft Office, update to a version that properly handles objects in memory to prevent remote code execution. For Microsoft Office 365, update to a version that properly handles objects in memory to prevent remote code execution. As a temporary workaround, consider restricting access to specially crafted files until a patch is available.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02189
CVE-2020-0991

Affected Products

Office
Office 365