CVE-2020-16934

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/10/2020
Last modified:
31/12/2023

Description

An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files. An attacker who successfully exploited the vulnerability could elevate privileges.<br /> To exploit this vulnerability, an attacker would need to convince a user to open a specially crafted file.<br /> The security update addresses the vulnerability by correcting how Microsoft Office Click-to-Run (C2R) components handle these files.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office:2019:*:*:*:*:-:*:*
cpe:2.3:a:microsoft:office_2013_click-to-run:-:*:*:*:*:*:*:*