VDB

CVE-2020-1342

CVE-2020-1342 PUBLISHED CVSS 5.5 MEDIUM

An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1445.

EPSS 24.81% · 96.2th percentile

Risk Scores

CVSS v3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
24.81%
96.2th percentile

Affected Products

VendorProductVersions
MicrosoftMicrosoft 365 Apps for Enterprise for 64-bit Systemsunspecified
MicrosoftMicrosoft SharePoint Server2019, 2010 Service Pack 2
MicrosoftMicrosoft Office2019 for 64-bit editions, 2016 for Mac, *
MicrosoftMicrosoft 365 Apps for Enterprise for 32-bit Systems*
microsoft365_apps
microsoftsharepoint_server2019, 2010
MicrosoftMicrosoft SharePoint Enterprise Server*, 2016
MicrosoftMicrosoft Office Online Serverunspecified
microsoftoffice_online_server
microsoftword2010, 2013, 2016
MicrosoftMicrosoft Office Web Apps*, 2010 Service Pack 2
microsoftsharepoint_enterprise_server2013, 2016
microsoftoffice2016, 2019, 2019
MicrosoftMicrosoft Word2013 Service Pack 1 (64-bit editions), 2010 Service Pack 2 (64-bit editions), 2010 Service Pack 2 (32-bit editions)
microsoftoffice_web_apps2013, 2010

Timeline

  • Jul 14, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 22, 2021 EPSS Score
  • Oct 25, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 27, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 5, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 10, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›