CVE-2020-1445
Description
An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka Microsoft Office Information Disclosure Vulnerability. This CVE ID is unique from CVE-2020-1342.
Risk Information
Base Score
5.5
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
27.512
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Microsoft Word Remote Code Execution Vulnerability for Microsoft Office Web Apps Server 2013 (KB4484357) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft Word 2013 (KB4484446) 32-Bit Edition | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft Word 2013 (KB4484446) 64-Bit Edition | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft Word 2016 (KB4484438) 32-Bit Edition | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft Word 2016 (KB4484438) 64-Bit Edition | Windows |
| Microsoft Office Information Disclosure Vulnerability for Microsoft SharePoint Enterprise Server 2013 (KB4484348) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft Word 2010 (KB4484458) 32-Bit Edition | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft Word 2010 (KB4484458) 64-Bit Edition | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft Office 2010 (KB4484456) 32-Bit Edition | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft Office 2010 (KB4484456) 64-Bit Edition | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft Web Applications (KB4484381) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft SharePoint Server 2010 (KB4484370) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2002 of version(12527.20880) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2002 of version(12527.20880) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x64 2002 of version(12527.20880) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x86 2002 of version(12527.20880) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x64 2002 of version(12527.20880) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x86 2002 of version(12527.20880) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Targeted Channel Version 2002 (Build 12527.20880) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi-Annual Channel Version 2002 (Build 12527.20880) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Monthly Channel for x64 2006 of version(13001.20384) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Monthly Channel for x86 2006 of version(13001.20384) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Monthly Channel for x64 2006 of version(13001.20384) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Monthly Channel for x86 2006 of version(13001.20384) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Monthly Channel Version 2006 (Build 13001.20384) | Windows |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-29294 | Security Update for Microsoft Office Web Apps Server 2013 (KB4484357) |
| PATCH-29298 | Security Update for Microsoft Word 2013 (KB4484446) 32-Bit Edition |
| PATCH-29301 | Security Update for Microsoft Word 2013 (KB4484446) 64-Bit Edition |
| PATCH-29306 | Security Update for Microsoft Word 2016 (KB4484438) 32-Bit Edition |
| PATCH-29307 | Security Update for Microsoft Word 2016 (KB4484438) 64-Bit Edition |
| PATCH-29297 | Security Update for Microsoft SharePoint Enterprise Server 2013 (KB4484348) |
| PATCH-29283 | Security Update for Microsoft Office 2010 (KB4484456) 32-Bit Edition |
| PATCH-29286 | Security Update for Microsoft Office 2010 (KB4484456) 64-Bit Edition |
| PATCH-29436 | Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2002 of version(12527.20880) |
| PATCH-29438 | Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2002 of version(12527.20880) |
| PATCH-29440 | Update for Microsoft 365 Apps for Business Semi Annual Channel for x64 2002 of version(12527.20880) |
| PATCH-29442 | Update for Microsoft 365 Apps for Business Semi Annual Channel for x86 2002 of version(12527.20880) |
| PATCH-29444 | Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x64 2002 of version(12527.20880) |
| PATCH-29446 | Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x86 2002 of version(12527.20880) |
| PATCH-29451 | Update for Microsoft 365 Apps for Enterprise Targeted Channel Version 2002 (Build 12527.20880) |
| PATCH-29452 | Update for Microsoft 365 Apps for Enterprise Semi-Annual Channel Version 2002 (Build 12527.20880) |
| PATCH-29428 | Update for Microsoft 365 Apps for Enterprise Monthly Channel for x64 2006 of version(13001.20384) |
| PATCH-29430 | Update for Microsoft 365 Apps for Enterprise Monthly Channel for x86 2006 of version(13001.20384) |
| PATCH-29432 | Update for Microsoft 365 Apps for Business Monthly Channel for x64 2006 of version(13001.20384) |
| PATCH-29434 | Update for Microsoft 365 Apps for Business Monthly Channel for x86 2006 of version(13001.20384) |
| PATCH-29453 | Update for Microsoft 365 Apps for Enterprise Monthly Channel Version 2006 (Build 13001.20384) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234