CVE-2020-17062
published 2020-11-11CVE-2020-17062: Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
PriorityP342high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
3.82%
88.9th percentile
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2010_service_pack_2 | >= 13.0.0.0 < publication | publication |
| microsoft | microsoft_office_2013_service_pack_1 | >= 15.0.0 < publication | publication |
| microsoft | microsoft_office_2016 | >= 16.0.0 < publication | publication |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_office_2010_service_pack_2 | — | — |
| msrc | microsoft_office_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_office_2013_service_pack_1 | — | — |
| msrc | microsoft_office_2016 | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8m83-fq97-5qgm: Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2020-17062 [HIGH] GHSA-8m83-fq97-5qgm: Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Microsoft
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
vendor_msrc·2020-11-10·CVSS 7.8
CVE-2020-17062 [HIGH] Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
Microsoft Office: Microsoft Office
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Click to Run
Reference: https://www.microsoft.com/download/details.aspx?familyid=1db01dbb-2c09-4223-b475-293c5713d319
Reference: https://www.microsoft.com/download/details.aspx?familyid=7cfece7d-a36c-4687-92e1-b69e75f3ab58
Reference: https://www.microsoft.com/download/details.aspx?familyid=6dc44de5-796c-45a4-8fa
No detection rules found.
No public exploits indexed.
Unit42
Unit 42 Discovers 15 New Vulnerabilities Across Microsoft, Adobe and Apple Products
blogs_unit42·2021-03-19·CVSS 6.1
[MEDIUM] Unit 42 Discovers 15 New Vulnerabilities Across Microsoft, Adobe and Apple Products
## Executive Summary
Unit 42 researchers have been credited with discovering 15 new vulnerabilities addressed by the Microsoft Security Response Center (MSRC), Adobe Security Bulletin and Apple Security Updates, as part of the last quarter of security update releases.
## Vulnerabilities
Of the 15 new vulnerabilities credited to Unit 42 researchers, 10 come from Microsoft with severity ratings from low to important. The four Adobe Reader DC vulnerabilities are all critical bugs that allow remote code execution (RCE). Lastly, there is an Apple cross site scripting (XSS) vulnerability that could also lead to arbitrary RCE in the context of the currently logged in user.
The Unit 42 researchers credited are Tao Yan, Zhibin Zhang, Bo Qu, Ronen Haber and Ken Hsu.
The recently discovered vuln
Unit42
Unit 42 Discovers 15 New Vulnerabilities Across Microsoft, Adobe and Apple Products
blogs_unit42·2021-03-19·CVSS 7.1
[HIGH] Unit 42 Discovers 15 New Vulnerabilities Across Microsoft, Adobe and Apple Products
Threat Research Center
Threat Research
Vulnerabilities
## Unit 42 Discovers 15 New Vulnerabilities Across Microsoft, Adobe and Apple Products
Bo Qu
Published: March 19, 2021
Threat Research
Vulnerabilities
Adobe
Apple
Black Hat
Microsoft
Microsoft Security Response Center (MSRC)
MSRC
Privilege escalation
Remote Code Execution
## Executive Summary
Unit 42 researchers have been credited with discovering 15 new vulnerabilities addressed by the Microsoft Security Response Center (MSRC) , Adobe Security Bulletin and Apple Security Updates , as part of the last quarter of security update releases.
## Vulnerabilities
Of the 15 new vulnerabilities credited to Unit 42 researchers, 10 come from Microsoft with severity ratings from low to important. The four Adobe Reader DC v
2020-11-11
Published