First published: Thu Mar 12 2020(Updated: )
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0851, CVE-2020-0852, CVE-2020-0855, CVE-2020-0892.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2016 | |
Microsoft Office | =2019 | |
Microsoft Office | =2019 | |
Microsoft Office 365 Proplus | ||
Microsoft Office Online Server | =1.0 | |
Microsoft SharePoint Enterprise Server | =2013-sp1 | |
Microsoft SharePoint Enterprise Server | =2016 | |
Microsoft SharePoint Foundation | =2013-sp1 | |
Microsoft SharePoint Server | =2019 | |
Microsoft Word | =2013-sp1 | |
Microsoft Word | =2013-sp1 | |
Microsoft Word | =2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-0850 is a remote code execution vulnerability in Microsoft Word software.
The severity of CVE-2020-0850 is high, with a CVSS score of 8.8.
Microsoft Office 2016, Microsoft Office 2019, and Microsoft Office 365 Proplus are affected by CVE-2020-0850.
CVE-2020-0850 exploits the vulnerability by improperly handling objects in memory in Microsoft Word.
Yes, Microsoft has released a security advisory with guidance on how to mitigate the vulnerability. Please refer to the Microsoft Security Guidance advisory for more information.