PT-2020-4026 · Microsoft · Office Word+1
Published
2020-09-08
·
Updated
2023-12-31
·
CVE-2020-1338
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Microsoft Word (affected versions not specified)
Description:
A remote code execution issue exists in Microsoft Word software due to its failure to properly handle objects in memory. This could allow an attacker to use a specially crafted file to perform actions in the security context of the current user, potentially taking actions on behalf of the logged-on user with the same permissions. The vulnerability can be exploited by convincing a user to open a specially crafted file, which could be sent via email or hosted on a website. The attacker would need to entice the user to click a link and then open the file. The issue is related to errors in processing objects in memory.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office Word
Sharepoint Server