cbcvebase.
CVE-2020-1322
published 2020-06-09

CVE-2020-1322: An information disclosure vulnerability exists when Microsoft Project reads out of bound memory due to an uninitialized variable, aka 'Microsoft Project…

PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
5.48%
91.9th percentile
An information disclosure vulnerability exists when Microsoft Project reads out of bound memory due to an uninitialized variable, aka 'Microsoft Project Information Disclosure Vulnerability'.

Affected

21 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_365_apps_for_enterprise_for_32-bit_systems
microsoftmicrosoft_365_apps_for_enterprise_for_64-bit_systems
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_project
microsoftmicrosoft_project
microsoftmicrosoft_project
microsoftmicrosoft_project
microsoftmicrosoft_project
microsoftmicrosoft_project
microsoftoffice
microsoftproject
microsoftproject
microsoftproject
msrcmicrosoft_365_apps_for_enterprise_for_32-bit_systems
msrcmicrosoft_365_apps_for_enterprise_for_64-bit_systems
msrcmicrosoft_office_2019_for_32-bit_editions
msrcmicrosoft_office_2019_for_64-bit_editions
msrcmicrosoft_project_2010_service_pack_2
msrcmicrosoft_project_2013_service_pack_1
msrcmicrosoft_project_2016

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_msrc6.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.