VDB

CVE-2020-1447

CVE-2020-1447 PUBLISHED CVSS 8.800000190734863 HIGH

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1448.

EPSS 45.95% · 97.7th percentile

Risk Scores

CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
45.95%
97.7th percentile

Affected Products

VendorProductVersions
MicrosoftMicrosoft Office Online Serverunspecified
microsoftoffice2016, 2019, 2010
microsoftsharepoint_enterprise_server2013, 2016
microsoft365_apps
microsoftoffice_online_server1.0
microsoftword_rt2013
MicrosoftMicrosoft Office*, 2010 Service Pack 2 (64-bit editions), 2010 Service Pack 2 (32-bit editions)
MicrosoftMicrosoft Office Web Apps2013 Service Pack 1, 2010 Service Pack 2
MicrosoftMicrosoft 365 Apps for Enterprise for 64-bit Systemsunspecified
microsoftsharepoint_server2019, 2010
microsoftoffice_web_apps2013, 2010
MicrosoftMicrosoft Word*, 2013 Service Pack 1 (32-bit editions), 2013 RT Service Pack 1
MicrosoftMicrosoft SharePoint Enterprise Server2016, 2013 Service Pack 1
MicrosoftMicrosoft 365 Apps for Enterprise for 32-bit Systemsunspecified
microsoftword2013, 2010, 2016
MicrosoftMicrosoft SharePoint Server2010 Service Pack 2, 2019

Timeline

  • Jul 14, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 30, 2023 EPSS Score
  • May 13, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›