First published: Tue Jun 09 2020(Updated: )
A remote code execution vulnerability exists when Microsoft Word for Android fails to properly handle certain files.To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file.The update addresses the vulnerability by correcting how Microsoft Word for Android handles specially crafted URL files., aka 'Word for Android Remote Code Execution Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Word |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1223 is a remote code execution vulnerability in Microsoft Word for Android.
CVE-2020-1223 occurs when Microsoft Word for Android fails to properly handle certain files.
CVE-2020-1223 can be exploited by convincing a user to open a specially crafted URL file.
CVE-2020-1223 has a severity rating of 8.8, which is considered high.
CVE-2020-1223 can be fixed by applying the update provided by Microsoft to correct how Word for Android handles files.