CVE-2020-1448 PUBLISHED CVSS 8.800000190734863 HIGH

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1447.

EPSS 39.26% · 97.3th percentile

Risk Scores

CVSS v3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
39.26%
97.3th percentile

Affected Products

VendorProductVersions
MicrosoftMicrosoft SharePoint Enterprise Server2016
microsoftword2016, 2013
microsoftoffice2019
MicrosoftMicrosoft Word2013 Service Pack 1 (32-bit editions), 2013 Service Pack 1 (64-bit editions), 2016 (32-bit edition)
MicrosoftMicrosoft SharePoint Server2019
MicrosoftMicrosoft Office Online Serverunspecified
microsoftword_rt2013
microsoftsharepoint_server2019
microsoftsharepoint_enterprise_server2016
microsoftoffice_online_server1.0
microsoftoffice_web_apps2013
MicrosoftMicrosoft Office2019 for 32-bit editions, 2019 for 64-bit editions
MicrosoftMicrosoft Office Web Apps2013 Service Pack 1

Timeline

References

Open in Interactive Console →