CVE-2020-1224
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2020
Last modified:
31/12/2023
Description
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data.<br />
To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker must know the memory address location where the object was created.<br />
The update addresses the vulnerability by changing the way certain Excel functions handle objects in memory.<br />
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:*:* | ||
cpe:2.3:a:microsoft:excel:2010:sp2:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:excel:2013:sp1:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:excel:2013:sp1:*:*:rt:*:*:* | ||
cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:office:2016:*:*:*:*:macos:*:* | ||
cpe:2.3:a:microsoft:office:2019:*:*:*:*:-:*:* | ||
cpe:2.3:a:microsoft:office:2019:*:*:*:*:macos:*:* | ||
cpe:2.3:a:microsoft:office_online_server:-:*:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:office_web_apps:2013:sp1:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:sharepoint_enterprise_server:2013:sp1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page