cbcvebase.
CVE-2020-1446
published 2020-07-14

CVE-2020-1446: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code…

PriorityP354high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
11.28%
95.5th percentile
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448.

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office_online_server
microsoftmicrosoft_office_web_apps
microsoftmicrosoft_sharepoint_enterprise_server
microsoftmicrosoft_sharepoint_server
microsoftmicrosoft_word
microsoftmicrosoft_word
microsoftmicrosoft_word
microsoftmicrosoft_word
microsoftmicrosoft_word
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice_online_server
microsoftoffice_web_apps
microsoftoffice_web_apps
microsoftsharepoint_enterprise_server
microsoftsharepoint_enterprise_server
microsoftsharepoint_server
microsoftsharepoint_server
microsoftword
microsoftword
microsoftword
microsoftword_rt

Detection & IOCsextracted from sources · hover to see the quote

  • Attack vector requires a user to open a specially crafted Microsoft Word file; the Preview Pane is NOT an attack vector, so detections should focus on file-open events rather than preview events.
  • Email-based delivery: attacker sends a specially crafted Word file as an attachment and convinces the user to open it — monitor for Word process spawning child processes after opening email attachments.
  • Web-based delivery: attacker hosts or compromises a website serving a specially crafted Word file — monitor for Word files downloaded via browser and subsequently opened.
  • Exploitation results in code execution in the security context of the current user — monitor for anomalous child processes spawned by WINWORD.EXE with the privileges of the logged-on user.
  • ·The Preview Pane is explicitly confirmed NOT to be an attack vector for this vulnerability; scope detection rules to file-open events only.
  • ·As of the advisory, the vulnerability had not been publicly disclosed or exploited in the wild; exploitation was rated 'Less Likely' for both latest and older software releases.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.