← Back to CVE List
Vulnerability Intelligence Report
Microsoft Word Information Disclosure Vulnerability

CVE-2020-1583

An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker must know the memory address location where the object was created. The update addresses the vulnerability by changing the way certain Word functions handle objects in memory.

No Active Exploit Signals
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:4.91%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
Microsoft Microsoft SharePoint Enterprise Server 2016 16.0.0 < publication (affected)
Microsoft Microsoft SharePoint Enterprise Server 2013 Service Pack 1 15.0.0 < publication (affected)
Microsoft Microsoft SharePoint Server 2019 16.0.0 < publication (affected)
Microsoft Microsoft Office 2019 19.0.0 < https://aka.ms/OfficeSecurityReleases (affected)
Microsoft Microsoft Office 2019 for Mac 16.0.0 < publication (affected)
Microsoft Microsoft Office Online Server 16.0.1 < publication (affected)
Microsoft Microsoft 365 Apps for Enterprise 16.0.1 < https://aka.ms/OfficeSecurityReleases (affected)
Microsoft Microsoft Word 2016 16.0.1 < publication (affected)
Microsoft Microsoft Office 2016 for Mac 16.0.0 < publication (affected)
Microsoft Microsoft Office 2010 Service Pack 2 13.0.0.0 < publication (affected)
Microsoft Microsoft Office Web Apps 2010 Service Pack 2 13.0.0 < publication (affected)
Microsoft Microsoft Office Web Apps 2013 Service Pack 1 15.0.0.0 < publication (affected)
Microsoft Microsoft SharePoint Server 2010 Service Pack 2 13.0.0.0 < publication (affected)
Microsoft Microsoft Word 2010 Service Pack 2 13.0.0.0 < publication (affected)
Microsoft Microsoft Word 2013 Service Pack 1 15.0.1 < publication (affected)
Microsoft Microsoft Word 2013 Service Pack 1 15.0.1 < publication (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
4.906%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMicrosoft Corporation · Vendor · USA
Reserved2019-11-04T00:00:00
Published2020-08-17T19:13:51
Patch Date2020-08-11
Last Updated2024-11-18T16:26:19

LINK COPIED TO CLIPBOARD