CVE-2020-1581Improper Privilege Management in Microsoft 365 Apps FOR Enterprise

Severity
7.8HIGHNVD
EPSS
9.7%
top 7.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 17
Latest updateMay 24

Description

An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) components handle objects in memory. An attacker who successfully exploited the vulnerability could elevate privileges. The attacker would need to already have the ability to execute code on the system. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The security update addresses the vulnerability by correcting how Microsoft Office Click

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

CVEListV5microsoft/microsoft_office_2013_click-to-run15.0.0.015.0.5571.1000
CVEListV5microsoft/microsoft_office_201919.0.0https://aka.ms/OfficeSecurityReleases
NVDmicrosoft/office2013, 2019+1
CVEListV5microsoft/microsoft_365_apps_for_enterprise16.0.1https://aka.ms/OfficeSecurityReleases

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wpjv-j566-pfwc: An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) components handle objects in memory, aka 'Microsoft2022-05-24
CVEList
Microsoft Office Click-to-Run Elevation of Privilege Vulnerability2020-08-17

📋Vendor Advisories

1
Microsoft
Microsoft Office Click-to-Run Elevation of Privilege Vulnerability2020-08-11
CVE-2020-1581 — Improper Privilege Management | cvebase