cbcvebase.
CVE-2020-1447
published 2020-07-14

CVE-2020-1447: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code…

PriorityP353high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
10.68%
95.3th percentile
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1448.

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office_online_server
microsoftmicrosoft_office_web_apps
microsoftmicrosoft_sharepoint_enterprise_server
microsoftmicrosoft_sharepoint_server
microsoftmicrosoft_word
microsoftmicrosoft_word
microsoftmicrosoft_word
microsoftmicrosoft_word
microsoftmicrosoft_word
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice_online_server
microsoftoffice_web_apps
microsoftoffice_web_apps
microsoftsharepoint_enterprise_server
microsoftsharepoint_enterprise_server
microsoftsharepoint_server
microsoftsharepoint_server
microsoftword
microsoftword
microsoftword
microsoftword_rt

Detection & IOCsextracted from sources · hover to see the quote

  • Attack vector requires a user to open a specially crafted Microsoft Word file; the Preview Pane is NOT an attack vector, so detections should focus on file-open events rather than preview events.
  • Email-based delivery is a primary attack scenario — monitor for Word file attachments (e.g., .doc, .docx, .rtf) delivered via email that are subsequently opened by Word processes.
  • Web-based delivery is a secondary attack scenario — monitor for Word files downloaded from websites and opened, particularly from compromised or attacker-controlled sites hosting user-provided content.
  • ·As of the advisory publication, this vulnerability had NOT been publicly disclosed or exploited in the wild; exploitation was rated 'Less Likely' for both latest and older software releases.
  • ·The Preview Pane is confirmed NOT an attack vector, so detections scoped only to preview-pane activity will miss this vulnerability.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.