First published: Tue Jul 14 2020(Updated: )
A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files, aka 'Microsoft Office Remote Code Execution Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft 365 Apps for enterprise |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1458 is rated as critical due to its potential for exploitation leading to remote code execution.
To mitigate CVE-2020-1458, ensure that your Microsoft Office software is updated to the latest version as provided by Microsoft.
CVE-2020-1458 affects Microsoft 365 Apps, particularly those that utilize dynamic link library loading.
Yes, CVE-2020-1458 can be exploited remotely if a user opens a specially crafted file.
The potential impacts of CVE-2020-1458 include the execution of arbitrary code and compromise of the affected system.