PT-2020-3186 · Microsoft · Windows Address Book+1

Published

2020-07-14

·

Updated

2024-02-05

·

CVE-2020-1410

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows Address Book (affected versions not specified)
Description A remote code execution issue exists due to improper processing of vcard files by Windows Address Book (WAB). An attacker can exploit this by sending a malicious vcard file that the victim opens using WAB, allowing the attacker to execute arbitrary code. The vulnerability is related to errors in processing objects in memory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2020-03484
CVE-2020-1410

Affected Products

Windows
Windows Address Book