CVE-2020-1224
published 2020-09-11CVE-2020-1224: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the…
PriorityP426medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
4.35%
90.1th percentile
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data.
To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker must know the memory address location where the object was created.
The update addresses the vulnerability by changing the way certain Excel functions handle objects in memory.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_excel_2010_service_pack_2 | >= 13.0.0.0 < publication | publication |
| microsoft | microsoft_excel_2013_service_pack_1 | >= 15.0.0.0 < publication | publication |
| microsoft | microsoft_excel_2016 | >= 16.0.0.0 < publication | publication |
| microsoft | microsoft_office_2016_for_mac | >= 16.0.0 < publication | publication |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2019_for_mac | >= 16.0.0 < publication | publication |
| microsoft | microsoft_office_online_server | >= 16.0.1 < publication | publication |
| microsoft | microsoft_office_web_apps_2013_service_pack_1 | >= 15.0.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_enterprise_server_2013_service_pack_1 | >= 15.0.0 < publication | publication |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office_web_apps | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_excel_2010_service_pack_2 | — | — |
| msrc | microsoft_excel_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_excel_2013_service_pack_1 | — | — |
| msrc | microsoft_excel_2016 | — | — |
| msrc | microsoft_office_2016_for_mac | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Excel Information Disclosure Vulnerability
vendor_msrc·2020-09-08·CVSS 5.5
CVE-2020-1224 [MEDIUM] Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data.
To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker must know the memory address location where the object was created.
The update addresses the vulnerability by changing the way certain Excel functions handle objects in memory.
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
FAQ: Are the updates for the Microsoft Office for Mac currently available?
The secu
GHSA
GHSA-rh7x-98m6-6q46: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information
ghsa_unreviewed·2022-05-24
CVE-2020-1224 [MEDIUM] CWE-200 GHSA-rh7x-98m6-6q46: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.
No detection rules found.
No public exploits indexed.
2020-09-11
Published