VDB

CVE-2020-0991

CVE-2020-0991 PUBLISHED CVSS 7.800000190734863 HIGH

A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0760.

EPSS 33.65% · 97.0th percentile

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
33.65%
97.0th percentile

Affected Products

VendorProductVersions
microsoftoffice2010, 2013, 2013
MicrosoftMicrosoft Office2013 RT Service Pack 1, 2013 Service Pack 1 (32-bit editions), 2013 Service Pack 1 (64-bit editions)
microsoftoffice_365_proplus
MicrosoftOffice 365 ProPlus32-bit Systems, 64-bit Systems

Timeline

  • Apr 15, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
  • Mar 8, 2023 EPSS Score
  • Mar 11, 2023 EPSS Score
  • Apr 4, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›