CVE-2020-0760Improper Input Validation in Microsoft Access

Severity
8.8HIGHNVD
EPSS
33.5%
top 3.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 15
Latest updateMay 24

Description

A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0991.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages21 packages

NVDmicrosoft/office4 versions+3
CVEListV5microsoft/microsoft_office9 versions+8
CVEListV5microsoft/office_365_proplus32-bit Systems, 64-bit Systems+1
NVDmicrosoft/word2010, 2013, 2016+2
NVDmicrosoft/excel2010, 2013, 2016+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9v72-4g4q-gqfc: A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execut2022-05-24
CVEList
CVE-2020-0760: A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execut2020-04-15

📋Vendor Advisories

1
Microsoft
Microsoft Office Remote Code Execution Vulnerability2020-04-14
CVE-2020-0760 — Improper Input Validation in Microsoft | cvebase