PT-2020-3819 · Microsoft · Office+3

Published

2020-08-11

·

Updated

2024-01-19

·

CVE-2020-1502

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Microsoft Word (affected versions not specified) Microsoft Office (affected versions not specified) Microsoft Office Online Server (affected versions not specified) SharePoint Server (affected versions not specified)
Description: An information disclosure issue exists due to improper memory handling in Microsoft Word, allowing an attacker to potentially compromise a user's computer or data. To exploit this, an attacker would need to craft a special document file and convince a user to open it, requiring knowledge of the memory address location where the object was created. The vulnerability is related to errors in processing objects in memory, which could allow an attacker to disclose protected information.
Recommendations: For Microsoft Word, consider restricting the use of certain functions that handle objects in memory until an update is applied. For Microsoft Office, Microsoft Office Online Server, and SharePoint Server, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04181
CVE-2020-1502

Affected Products

Office
Office Online Server
Office Word
Sharepoint Server