CVE-2020-1449
Description
A remote code execution vulnerability exists in Microsoft Project software when the software fails to check the source markup of a file, aka Microsoft Project Remote Code Execution Vulnerability.
Risk Information
Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
14.767
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Microsoft Project Remote Code Execution Vulnerability for Microsoft Project 2010 (KB4484463) 32-Bit Edition | Windows |
| Microsoft Project Remote Code Execution Vulnerability for Microsoft Project 2010 (KB4484463) 64-Bit Edition | Windows |
| Microsoft Project Remote Code Execution Vulnerability for Microsoft Project 2013 (KB4484450) 32-Bit Edition | Windows |
| Microsoft Project Remote Code Execution Vulnerability for Microsoft Project 2013 (KB4484450) 64-Bit Edition | Windows |
| Microsoft Project Remote Code Execution Vulnerability for Microsoft Project 2016 (KB4484441) 32-Bit Edition | Windows |
| Microsoft Project Remote Code Execution Vulnerability for Microsoft Project 2016 (KB4484441) 64-Bit Edition | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2002 of version(12527.20880) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2002 of version(12527.20880) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x64 2002 of version(12527.20880) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x86 2002 of version(12527.20880) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x64 2002 of version(12527.20880) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x86 2002 of version(12527.20880) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Targeted Channel Version 2002 (Build 12527.20880) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi-Annual Channel Version 2002 (Build 12527.20880) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Monthly Channel for x64 2006 of version(13001.20384) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Monthly Channel for x86 2006 of version(13001.20384) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Monthly Channel for x64 2006 of version(13001.20384) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Monthly Channel for x86 2006 of version(13001.20384) | Windows |
| Microsoft Word Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Monthly Channel Version 2006 (Build 13001.20384) | Windows |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-29296 | Security Update for Microsoft Project 2013 (KB4484450) 32-Bit Edition |
| PATCH-29302 | Security Update for Microsoft Project 2013 (KB4484450) 64-Bit Edition |
| PATCH-29308 | Security Update for Microsoft Project 2016 (KB4484441) 32-Bit Edition |
| PATCH-29311 | Security Update for Microsoft Project 2016 (KB4484441) 64-Bit Edition |
| PATCH-29436 | Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2002 of version(12527.20880) |
| PATCH-29438 | Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2002 of version(12527.20880) |
| PATCH-29440 | Update for Microsoft 365 Apps for Business Semi Annual Channel for x64 2002 of version(12527.20880) |
| PATCH-29442 | Update for Microsoft 365 Apps for Business Semi Annual Channel for x86 2002 of version(12527.20880) |
| PATCH-29444 | Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x64 2002 of version(12527.20880) |
| PATCH-29446 | Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x86 2002 of version(12527.20880) |
| PATCH-29451 | Update for Microsoft 365 Apps for Enterprise Targeted Channel Version 2002 (Build 12527.20880) |
| PATCH-29452 | Update for Microsoft 365 Apps for Enterprise Semi-Annual Channel Version 2002 (Build 12527.20880) |
| PATCH-29428 | Update for Microsoft 365 Apps for Enterprise Monthly Channel for x64 2006 of version(13001.20384) |
| PATCH-29430 | Update for Microsoft 365 Apps for Enterprise Monthly Channel for x86 2006 of version(13001.20384) |
| PATCH-29432 | Update for Microsoft 365 Apps for Business Monthly Channel for x64 2006 of version(13001.20384) |
| PATCH-29434 | Update for Microsoft 365 Apps for Business Monthly Channel for x86 2006 of version(13001.20384) |
| PATCH-29453 | Update for Microsoft 365 Apps for Enterprise Monthly Channel Version 2006 (Build 13001.20384) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234