CVE-2020-17123
published 2020-12-10CVE-2020-17123: Microsoft Excel Remote Code Execution Vulnerability
PriorityP342high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
3.43%
87.6th percentile
Microsoft Excel Remote Code Execution Vulnerability
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_excel_2010_service_pack_2 | >= 13.0.0.0 < publication | publication |
| microsoft | microsoft_excel_2013_service_pack_1 | >= 15.0.0.0 < publication | publication |
| microsoft | microsoft_excel_2016 | >= 16.0.0.0 < publication | publication |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2019_for_mac | >= 16.0.0 < publication | publication |
| microsoft | microsoft_office_web_apps_2013_service_pack_1 | >= 15.0.0.0 < publication | publication |
| microsoft | office_online_server | >= 1.0.0 < publication | publication |
| microsoft | office_web_apps | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_excel_2010_service_pack_2 | — | — |
| msrc | microsoft_excel_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_excel_2013_service_pack_1 | — | — |
| msrc | microsoft_excel_2016 | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_office_2019_for_mac | — | — |
| msrc | microsoft_office_web_apps_2013_service_pack_1 | — | — |
| msrc | office_online_server | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Excel Remote Code Execution Vulnerability
vendor_msrc·2020-12-08·CVSS 7.8
CVE-2020-17123 [HIGH] Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
FAQ: Are the updates for the Microsoft Office 2019 for Mac currently available?
The security update for Microsoft Office 2019 for Mac is not immediately available. The update will be released as soon as possible, and when it is available, customers will be notified via a revision to this CVE information.
Microsoft Office: Microsoft Office
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Reference: https://www.microsoft.com/download/details.aspx
GHSA
GHSA-4x66-p4cq-54jr: , aka 'Microsoft Excel Remote Code Execution Vulnerability'
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-17127 [HIGH] GHSA-4x66-p4cq-54jr: , aka 'Microsoft Excel Remote Code Execution Vulnerability'
, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-17122, CVE-2020-17123, CVE-2020-17125, CVE-2020-17128, CVE-2020-17129.
GHSA
GHSA-324r-mgqm-8gjq: , aka 'Microsoft Excel Remote Code Execution Vulnerability'
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-17128 [HIGH] GHSA-324r-mgqm-8gjq: , aka 'Microsoft Excel Remote Code Execution Vulnerability'
, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-17122, CVE-2020-17123, CVE-2020-17125, CVE-2020-17127, CVE-2020-17129.
GHSA
GHSA-x3xh-fjmw-xggv: , aka 'Microsoft Excel Remote Code Execution Vulnerability'
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-17129 [HIGH] GHSA-x3xh-fjmw-xggv: , aka 'Microsoft Excel Remote Code Execution Vulnerability'
, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-17122, CVE-2020-17123, CVE-2020-17125, CVE-2020-17127, CVE-2020-17128.
GHSA
GHSA-4q2p-8m3f-h868: , aka 'Microsoft Excel Remote Code Execution Vulnerability'
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-17123 [HIGH] GHSA-4q2p-8m3f-h868: , aka 'Microsoft Excel Remote Code Execution Vulnerability'
, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-17122, CVE-2020-17125, CVE-2020-17127, CVE-2020-17128, CVE-2020-17129.
GHSA
GHSA-gpjj-hrg6-gr63: , aka 'Microsoft Excel Remote Code Execution Vulnerability'
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-17125 [HIGH] GHSA-gpjj-hrg6-gr63: , aka 'Microsoft Excel Remote Code Execution Vulnerability'
, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-17122, CVE-2020-17123, CVE-2020-17127, CVE-2020-17128, CVE-2020-17129.
GHSA
GHSA-mq2j-j89w-pvx3: , aka 'Microsoft Excel Remote Code Execution Vulnerability'
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-17122 [HIGH] GHSA-mq2j-j89w-pvx3: , aka 'Microsoft Excel Remote Code Execution Vulnerability'
, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-17123, CVE-2020-17125, CVE-2020-17127, CVE-2020-17128, CVE-2020-17129.
No detection rules found.
No public exploits indexed.
Tenable
Microsoft’s December 2020 Patch Tuesday Addresses 58 CVEs including CVE-2020-25705 (SAD DNS)
blogs_tenable·2020-12-08·CVSS 7.4
[HIGH] Microsoft’s December 2020 Patch Tuesday Addresses 58 CVEs including CVE-2020-25705 (SAD DNS)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Vulnerability Spotlight: Code execution vulnerability in Microsoft Excel
blogs_talos·2020-12-08·CVSS 7.8
[HIGH] Vulnerability Spotlight: Code execution vulnerability in Microsoft Excel
Marcin “Icewall” Noga of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Cisco Talos recently discovered a code execution vulnerability in some versions of Microsoft Excel. An
attacker could exploit this vulnerability by tricking the victim into opening a specially crafted XLS file, triggering a use-after-free condition and allowing them to execute remote code on the victim machine. Microsoft disclosed and patched this bug as part of their monthly security update Tuesday. For more on their updates, read the full blog here.
In accordance with our coordinated disclosure policy, Cisco Talos worked with Microsoft to ensure that these issues are resolved and that an update is available for affected customers.
## Vulnerability details
Microsoft Office ElementType code executi
Talos
Vulnerability Spotlight: Code execution vulnerability in Microsoft Excel
blogs_talos·2020-12-08·CVSS 7.8
[HIGH] Vulnerability Spotlight: Code execution vulnerability in Microsoft Excel
## Vulnerability Spotlight: Code execution vulnerability in Microsoft Excel
Marcin “Icewall” Noga of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Cisco Talos recently discovered a code execution vulnerability in some versions of Microsoft Excel. An attacker could exploit this vulnerability by tricking the victim into opening a specially crafted XLS file, triggering a use-after-free condition and allowing them to execute remote code on the victim machine. Microsoft disclosed and patched this bug as part of their monthly security update Tuesday. For more on their updates, read the full blog here .
In accordance with our coordinated disclosure policy, Cisco Talos worked with Microsoft to ensure that these issues are resolved and that an update is available for affected c
2020-12-10
Published