CVE-2020-1223
published 2020-06-09CVE-2020-1223: A remote code execution vulnerability exists when Microsoft Word for Android fails to properly handle certain files.To exploit the vulnerability, an attacker…
PriorityP353high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
8.04%
94.1th percentile
A remote code execution vulnerability exists when Microsoft Word for Android fails to properly handle certain files.To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file.The update addresses the vulnerability by correcting how Microsoft Word for Android handles specially crafted URL files., aka 'Word for Android Remote Code Execution Vulnerability'.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_word_for_android | — | — |
| msrc | microsoft_word_for_android | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered by opening a specially crafted URL file in Microsoft Word for Android; detection should focus on delivery of malicious URL files to Android Word app users. ↗
- →Talos Snort rules covering June 2020 Patch Tuesday vulnerabilities (which include CVE-2020-1223) are SIDs: 52213-52217, 54191-54194, 54219, 54220, 54230-54240, 54245-54250, 54270, 54271. ↗
- ·The Talos Snort rule SIDs listed cover the broader June 2020 Patch Tuesday release and are not confirmed to be exclusively mapped to CVE-2020-1223; specific SID-to-CVE mapping requires verification against the Snort advisory. ↗
- ·As of disclosure, this vulnerability had not been exploited in the wild and was rated 'Exploitation Less Likely' by Microsoft. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Word for Android Remote Code Execution Vulnerability
vendor_msrc·2020-06-09·CVSS 8.8
CVE-2020-1223 [HIGH] Word for Android Remote Code Execution Vulnerability
Word for Android Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Microsoft Word for Android fails to properly handle certain files.
To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file.
The update addresses the vulnerability by correcting how Microsoft Word for Android handles specially crafted URL files.
FAQ: How do I get the update for Microsoft Word for Android?
Tap the Google Play icon on your home screen.
Swipe in from the left edge of the screen.
Tap My apps & games.
Tap the Update box next to the Microsoft Word app.
Is there a direct link on the web?
Yes: https://play.google.com/store/apps/details?id=com.microsoft.office.word&hl=en_US
Android App: Android App
Microsoft: M
GHSA
GHSA-jwch-v5xr-vmcf: A remote code execution vulnerability exists when Microsoft Word for Android fails to properly handle certain files
ghsa_unreviewed·2022-05-24
CVE-2020-1223 [MEDIUM] CWE-20 GHSA-jwch-v5xr-vmcf: A remote code execution vulnerability exists when Microsoft Word for Android fails to properly handle certain files
A remote code execution vulnerability exists when Microsoft Word for Android fails to properly handle certain files.To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file.The update addresses the vulnerability by correcting how Microsoft Word for Android handles specially crafted URL files., aka 'Word for Android Remote Code Execution Vulnerability'.
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday for June 2020 — Snort rules and prominent vulnerabilities
blogs_talos·2020-06-10·CVSS 8.8
[HIGH] Microsoft Patch Tuesday for June 2020 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for June 2020 — Snort rules and prominent vulnerabilities
By Jon Munshaw.
Microsoft released its monthly security update Tuesday, disclosing more than 120 vulnerabilities across its array of products.
While none of the vulnerabilities disclosed have been exploited in the wild, users of all Microsoft and Windows products are urged to update their software as soon as possible to avoid possible exploitation.
The security updates cover several different products including the VBScript engine, SharePoint file-sharing service and GDI+. Talos also released a new set of SNORTⓇ rules that provide coverage for some of these vulnerabilities. For complete details, check out the latest Snort advisory here .
One of the most urgent patches concerns CVE-2020-1248, a remote
Talos
Microsoft Patch Tuesday for June 2020 — Snort rules and prominent vulnerabilities
blogs_talos·2020-06-10·CVSS 8.8
[HIGH] Microsoft Patch Tuesday for June 2020 — Snort rules and prominent vulnerabilities
By Jon Munshaw.
Microsoft released its monthly security update Tuesday, disclosing more than 120 vulnerabilities across its array of products.
While none of the vulnerabilities disclosed have been exploited in the wild, users of all Microsoft and Windows products are urged to update their software as soon as possible to avoid possible exploitation.
The security updates cover several different products including the VBScript engine, SharePoint file-sharing service and GDI+.
Talos also released a new set of SNORTⓇ rules that provide coverage for some of these vulnerabilities. For complete details, check out the latest Snort advisory here.
One of the most urgent patches concerns CVE-2020-1248, a remote code execution vulnerability in the Windows Graphics Device Interface (GDI). An attack
2020-06-09
Published