PT-2020-2809 · Microsoft · Office Project

Published

2020-06-09

·

Updated

2021-07-21

·

CVE-2020-1322

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Project (affected versions not specified)
Description An information disclosure issue exists due to Microsoft Project reading out of bound memory caused by an uninitialized variable. This could allow a remote attacker to gain unauthorized access to protected information. Exploitation requires a user to open a specially crafted file with an affected version of Microsoft Project, potentially allowing the attacker to view sensitive information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Information Disclosure

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02937
CVE-2020-1322

Affected Products

Office Project