PT-2020-2741 · Microsoft · Office+2
Published
2020-06-09
·
Updated
2021-07-21
·
CVE-2020-1229
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Outlook (affected versions not specified)
Description
A security feature bypass issue exists when Office fails to enforce security settings configured on a system. This could allow a remote attacker to bypass existing security restrictions. Exploitation requires a user to open a specially crafted image with an affected version of Microsoft Office software, potentially causing the system to load remote images and disclose the IP address of the targeted system to the attacker.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office
Outlook
Office Word