cbcvebase.
CVE-2020-1321
published 2020-06-09

CVE-2020-1321: A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory, aka 'Microsoft Office Remote Code…

PriorityP354high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
11.63%
95.6th percentile
A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory, aka 'Microsoft Office Remote Code Execution Vulnerability'.

Affected

70 ranges· showing 25
VendorProductVersion rangeFixed in
ajv.jsajv>= 0 < 6.12.36.12.3
aws-sdkshared-ini-file-loader>= 0 < 1.0.0-rc.91.0.0-rc.9
bmoor_projectbmoor>= 0 < 0.10.10.10.1
chaijispathval>= 0 < 1.1.11.1.1
class-transformer_projectclass-transformer>= 0 < 0.3.10.3.1
confinit_projectconfinit>= 0 < 0.4.00.4.0
connie-lang_projectconnie-lang>= 0 < 0.1.10.1.1
deep-set_projectdeep-set1.0.0 – 1.0.1
dot-prop_projectdot-prop>= 0 < 4.2.14.2.1
dot-prop_projectdot-prop>= 5.0.0 < 5.1.15.1.1
eivifjdot>= 0 < 1.0.31.0.3
exodusfield0.0.1 – 1.0.1
fun-map_projectfun-map0 – 3.3.1
grpcgrpc>= 0 < 1.24.41.24.4
grpcgrpc-js>= 0 < 1.1.81.1.8
hapihoek>= 0 < 8.5.18.5.1
hapihoek>= 9.0.0 < 9.0.39.0.3
hapijshoek0 – 6.1.3
immer_projectimmer>= 7.0.0 < 9.0.69.0.6
js-datajs-data0 – 3.0.10
js-ini_projectjs-ini>= 0 < 1.3.01.3.0
json-pointer_projectjson-pointer>= 0 < 0.6.20.6.2
libnested_projectlibnested>= 0 < 1.5.21.5.2
linuxfoundationdojo>= 0 < 1.11.101.11.10
linuxfoundationdojo>= 1.12.0 < 1.12.81.12.8

Detection & IOCsextracted from sources · hover to see the quote

  • Attack vector requires a user to open a specially crafted file with an affected version of Microsoft Office software; the Preview Pane is NOT an attack vector
  • Web-based delivery vector: attacker hosts or leverages a compromised website serving a specially crafted Office file to exploit the vulnerability
  • Preview Pane is confirmed NOT an attack vector — detections should focus on full file-open events in Office processes, not preview rendering
  • ·Patches for Microsoft Office 2016 for Mac and Microsoft Office 2019 for Mac were not immediately available at time of advisory publication; detection coverage on Mac endpoints may be incomplete until patched
  • ·Exploit status at time of advisory: not publicly disclosed and not exploited in the wild; exploitation assessed as 'Less Likely' for both latest and older software releases

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa9.8CRITICAL
vendor_msrc8.8HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.