CVE-2020-1446
published 2020-07-14CVE-2020-1446: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code…
PriorityP354high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
11.28%
95.5th percentile
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office_online_server | — | — |
| microsoft | microsoft_office_web_apps | — | — |
| microsoft | microsoft_sharepoint_enterprise_server | — | — |
| microsoft | microsoft_sharepoint_server | — | — |
| microsoft | microsoft_word | — | — |
| microsoft | microsoft_word | — | — |
| microsoft | microsoft_word | — | — |
| microsoft | microsoft_word | — | — |
| microsoft | microsoft_word | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office_online_server | — | — |
| microsoft | office_web_apps | — | — |
| microsoft | office_web_apps | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| microsoft | word_rt | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Attack vector requires a user to open a specially crafted Microsoft Word file; the Preview Pane is NOT an attack vector, so detections should focus on file-open events rather than preview events. ↗
- →Email-based delivery: attacker sends a specially crafted Word file as an attachment and convinces the user to open it — monitor for Word process spawning child processes after opening email attachments. ↗
- →Web-based delivery: attacker hosts or compromises a website serving a specially crafted Word file — monitor for Word files downloaded via browser and subsequently opened. ↗
- →Exploitation results in code execution in the security context of the current user — monitor for anomalous child processes spawned by WINWORD.EXE with the privileges of the logged-on user. ↗
- ·The Preview Pane is explicitly confirmed NOT to be an attack vector for this vulnerability; scope detection rules to file-open events only. ↗
- ·As of the advisory, the vulnerability had not been publicly disclosed or exploited in the wild; exploitation was rated 'Less Likely' for both latest and older software releases. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xw2w-mmgv-hf8h: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2020-1447 [HIGH] CWE-119 GHSA-xw2w-mmgv-hf8h: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1448.
GHSA
GHSA-9rh6-9x9j-x842: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2020-1448 [HIGH] CWE-119 GHSA-9rh6-9x9j-x842: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1447.
GHSA
GHSA-hhh7-3xf8-52v6: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2020-1446 [HIGH] CWE-119 GHSA-hhh7-3xf8-52v6: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448.
Microsoft
Microsoft Word Remote Code Execution Vulnerability
vendor_msrc·2020-07-14·CVSS 8.8
CVE-2020-1446 [HIGH] Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user.
To exploit the vulnerability, a user must open a specially crafted file with an affected version of Microsoft Word software. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attac
No detection rules found.
No public exploits indexed.
2020-07-14
Published