CVE-2020-1447 PUBLISHED CVSS 8.800000190734863 HIGH

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1448.

EPSS 45.95% · 97.6th percentile

Risk Scores

CVSS v3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
45.95%
97.6th percentile

Affected Products

VendorProductVersions
MicrosoftMicrosoft Office Online Serverunspecified
microsoftoffice2016, 2019, 2019
microsoftsharepoint_enterprise_server2016, 2013
microsoft365_apps
microsoftoffice_online_server1.0
microsoftword_rt2013
MicrosoftMicrosoft Office2019 for Mac, 2010 Service Pack 2 (64-bit editions), 2016 for Mac
MicrosoftMicrosoft Office Web Apps2010 Service Pack 2, 2013 Service Pack 1
MicrosoftMicrosoft 365 Apps for Enterprise for 64-bit Systemsunspecified
microsoftsharepoint_server2010, 2019
microsoftoffice_web_apps2010, 2013
MicrosoftMicrosoft Word2013 Service Pack 1 (64-bit editions), 2016 (32-bit edition), 2016 (64-bit edition)
MicrosoftMicrosoft SharePoint Enterprise Server2016, 2013 Service Pack 1
MicrosoftMicrosoft 365 Apps for Enterprise for 32-bit Systemsunspecified
microsoftword2010, 2013, 2016
MicrosoftMicrosoft SharePoint Server2010 Service Pack 2, 2019

Timeline

References

Open in Interactive Console →