CVE-2020-11536: Input Validation
Published Apr 15, 2020
·Updated
An issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit the unzip function to rewrite a binary and remotely execute code on a victim's server.
Affected Software
1 affected component
Onlyoffice Document Server=5.5.0
Event History
Apr 15, 2020
CVE Published
via MITRE·02:56 PM
Data Sourced
via MITRE·02:56 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-11536?
CVE-2020-11536 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2020-11536?
To fix CVE-2020-11536, you should upgrade ONLYOFFICE Document Server to the latest version that addresses the vulnerability.
3
What versions of ONLYOFFICE are affected by CVE-2020-11536?
CVE-2020-11536 specifically affects ONLYOFFICE Document Server version 5.5.0.
4
What is the impact of exploiting CVE-2020-11536?
Exploiting CVE-2020-11536 allows an attacker to execute arbitrary code on the victim's server.
5
Can CVE-2020-11536 be exploited via malicious document files?
Yes, CVE-2020-11536 can be exploited by crafting a malicious .docx file that targets the unzip function.