VDB

CVE-2020-1448

CVE-2020-1448 PUBLISHED CVSS 8.800000190734863 HIGH

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1447.

EPSS 36.74% · 97.2th percentile

Risk Scores

CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
36.74%
97.2th percentile

Affected Products

VendorProductVersions
MicrosoftMicrosoft SharePoint Enterprise Server2016
microsoftword2016, 2013
microsoftoffice2019
MicrosoftMicrosoft Word*, *, 2016 (32-bit edition)
MicrosoftMicrosoft SharePoint Server2019
MicrosoftMicrosoft Office Online Serverunspecified
microsoftword_rt2013
microsoftsharepoint_server2019
microsoftsharepoint_enterprise_server2016
microsoftoffice_online_server1.0
microsoftoffice_web_apps2013
MicrosoftMicrosoft Office*, 2019 for 64-bit editions
MicrosoftMicrosoft Office Web Apps2013 Service Pack 1

Timeline

  • Jul 14, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Mar 30, 2023 EPSS Score
  • Aug 17, 2023 EPSS Score
  • Aug 31, 2023 EPSS Score
  • Dec 2, 2023 EPSS Score
  • Aug 4, 2024 CVE Updated
  • Dec 17, 2024 EPSS Score
  • Mar 17, 2025 EPSS Score
  • Mar 19, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›