CVE-2020-0652

Description

A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka Microsoft Office Memory Corruption Vulnerability.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
16.67

Associated Vulnerability

VulnerabilityOS Platform
Microsoft Office Memory Corruption Vulnerability for Microsoft Office 2010 (KB4484236) 32-Bit EditionWindows
Microsoft Office Memory Corruption Vulnerability for Microsoft Office 2010 (KB4484236) 64-Bit EditionWindows
Microsoft Office Memory Corruption Vulnerability for Microsoft Office 2016 (KB4484221) 32-Bit EditionWindows
Microsoft Office Memory Corruption Vulnerability for Microsoft Office 2016 (KB4484221) 64-Bit EditionWindows
Microsoft Office Memory Corruption Vulnerability for Microsoft Office 2013 (KB4484227) 32-Bit EditionWindows
Microsoft Office Memory Corruption Vulnerability for Microsoft Office 2013 (KB4484227) 64-Bit EditionWindows
Microsoft Excel Remote Code Execution Vulnerability for Office 365 Professional Plus Semi Annual Targeted Channel for x64 1908 of version(11929.20562)Windows
Microsoft Excel Remote Code Execution Vulnerability for Office 365 Professional Plus Semi Annual Targeted Channel for x86 1908 of version(11929.20562)Windows
Microsoft Excel Remote Code Execution Vulnerability for Office 365 Targeted Channel Version 1908 (Build 11929.20562)Windows
Microsoft Excel Remote Code Execution Vulnerability for Office 365 Professional Plus Monthly Channel for x64 1912 of version(12325.20298)Windows
Microsoft Excel Remote Code Execution Vulnerability for Office 365 Professional Plus Monthly Channel for x86 1912 of version(12325.20298)Windows
Microsoft Excel Remote Code Execution Vulnerability for Office 365 Business Edition Monthly Channel for x64 1912 of version(12325.20298)Windows
Microsoft Excel Remote Code Execution Vulnerability for Office 365 Business Edition Monthly Channel for x86 1912 of version(12325.20298)Windows
Microsoft Excel Remote Code Execution Vulnerability for Office 365 Monthly Channel Version 1912 (Build 12325.20298)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-28119Security Update for Microsoft Office 2016 (KB4484221) 32-Bit Edition
PATCH-28120Security Update for Microsoft Office 2016 (KB4484221) 64-Bit Edition
PATCH-28115Security Update for Microsoft Office 2013 (KB4484227) 32-Bit Edition
PATCH-28116Security Update for Microsoft Office 2013 (KB4484227) 64-Bit Edition
PATCH-28257Update for Office 365 Professional Plus Semi Annual Targeted Channel for x64 1908 of version(11929.20562)
PATCH-28259Update for Office 365 Professional Plus Semi Annual Targeted Channel for x86 1908 of version(11929.20562)
PATCH-28272Update for Office 365 Targeted Channel Version 1908 (Build 11929.20562)
PATCH-28247Update for Office 365 Professional Plus Monthly Channel for x64 1912 of version(12325.20298)
PATCH-28249Update for Office 365 Professional Plus Monthly Channel for x86 1912 of version(12325.20298)
PATCH-28251Update for Office 365 Business Edition Monthly Channel for x64 1912 of version(12325.20298)
PATCH-28253Update for Office 365 Business Edition Monthly Channel for x86 1912 of version(12325.20298)
PATCH-28271Update for Office 365 Monthly Channel Version 1912 (Build 12325.20298)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234