VDB

CVE-2020-1446

CVE-2020-1446 PUBLISHED CVSS 8.800000190734863 HIGH

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448.

EPSS 39.92% · 97.4th percentile

Risk Scores

CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
39.92%
97.4th percentile

Affected Products

VendorProductVersions
MicrosoftMicrosoft Office Online Serverunspecified
MicrosoftMicrosoft Office*, 2010 Service Pack 2 (32-bit editions), 2019 for Mac
microsoftoffice_online_server1.0
microsoftoffice2019, 2019, 2010
microsoftsharepoint_server2010, 2019
microsoftsharepoint_enterprise_server2013, 2016
MicrosoftMicrosoft 365 Apps for Enterprise for 32-bit Systemsunspecified
microsoft365_apps
MicrosoftMicrosoft Word2013 RT Service Pack 1, 2013 Service Pack 1 (64-bit editions), *
microsoftword_rt2013
MicrosoftMicrosoft Office Web Apps2013 Service Pack 1, 2010 Service Pack 2
microsoftword2010, 2013, 2016
MicrosoftMicrosoft 365 Apps for Enterprise for 64-bit Systemsunspecified
MicrosoftMicrosoft SharePoint Enterprise Server2016, 2013 Service Pack 1
MicrosoftMicrosoft SharePoint Server2010 Service Pack 2, 2019
microsoftoffice_web_apps2013, 2010

Timeline

  • Jul 14, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 30, 2023 EPSS Score
  • May 13, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›