CVE-2020-1446 PUBLISHED CVSS 8.800000190734863 HIGH

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448.

EPSS 39.92% · 97.3th percentile

Risk Scores

CVSS v3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
39.92%
97.3th percentile

Affected Products

VendorProductVersions
MicrosoftMicrosoft Office Online Serverunspecified
MicrosoftMicrosoft Office2016 for Mac, 2010 Service Pack 2 (32-bit editions), 2010 Service Pack 2 (64-bit editions)
microsoftoffice_online_server1.0
microsoftoffice2019, 2019, 2010
microsoftsharepoint_server2019, 2010
microsoftsharepoint_enterprise_server2013, 2016
MicrosoftMicrosoft 365 Apps for Enterprise for 32-bit Systemsunspecified
microsoft365_apps
MicrosoftMicrosoft Word2013 Service Pack 1 (32-bit editions), 2013 Service Pack 1 (64-bit editions), 2010 Service Pack 2 (64-bit editions)
microsoftword_rt2013
MicrosoftMicrosoft Office Web Apps2010 Service Pack 2, 2013 Service Pack 1
microsoftword2010, 2016, 2013
MicrosoftMicrosoft 365 Apps for Enterprise for 64-bit Systemsunspecified
MicrosoftMicrosoft SharePoint Enterprise Server2016, 2013 Service Pack 1
MicrosoftMicrosoft SharePoint Server2019, 2010 Service Pack 2
microsoftoffice_web_apps2013, 2010

Timeline

References

Open in Interactive Console →