cbcvebase.
CVE-2020-1322
published 2020-06-09

CVE-2020-1322: An information disclosure vulnerability exists when Microsoft Project reads out of bound memory due to an uninitialized variable, aka 'Microsoft Project…

PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
5.48%
92.3th percentile
An information disclosure vulnerability exists when Microsoft Project reads out of bound memory due to an uninitialized variable, aka 'Microsoft Project Information Disclosure Vulnerability'.

Affected

21 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_365_apps_for_enterprise_for_32-bit_systems——
microsoftmicrosoft_365_apps_for_enterprise_for_64-bit_systems——
microsoftmicrosoft_office——
microsoftmicrosoft_office——
microsoftmicrosoft_project——
microsoftmicrosoft_project——
microsoftmicrosoft_project——
microsoftmicrosoft_project——
microsoftmicrosoft_project——
microsoftmicrosoft_project——
microsoftoffice——
microsoftproject——
microsoftproject——
microsoftproject——
msrcmicrosoft_365_apps_for_enterprise_for_32-bit_systems——
msrcmicrosoft_365_apps_for_enterprise_for_64-bit_systems——
msrcmicrosoft_office_2019_for_32-bit_editions——
msrcmicrosoft_office_2019_for_64-bit_editions——
msrcmicrosoft_project_2010_service_pack_2——
msrcmicrosoft_project_2013_service_pack_1——
msrcmicrosoft_project_2016——

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_msrc6.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.