First published: Mon Aug 17 2020(Updated: )
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1494, CVE-2020-1496, CVE-2020-1498, CVE-2020-1504.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft 365 Apps for enterprise | ||
Microsoft Office Excel | =2010-sp2 | |
Microsoft Office Excel | =2013-sp1 | |
Microsoft Office Excel | =2013-sp1 | |
Microsoft Office Excel | =2016 | |
Microsoft Office | =2010-sp2 | |
Microsoft Office | =2013-sp1 | |
Microsoft Office | =2016 | |
Microsoft Office | =2016 | |
Microsoft Office | =2019 | |
Microsoft Office | =2019 | |
Microsoft Office Online Server | ||
Microsoft SharePoint Enterprise Server 2016 | =2013-sp1 | |
Microsoft SharePoint Server 2010 | =2010-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1495 has a critical severity rating as it can lead to remote code execution.
To mitigate CVE-2020-1495, you should apply the latest security updates provided by Microsoft for affected products.
CVE-2020-1495 affects Microsoft Excel, Microsoft Office, and SharePoint in various versions.
Yes, CVE-2020-1495 can be exploited remotely if a user opens a specially crafted Excel file.
The main risks include unauthorized access and control of the affected system, leading to data theft or further exploitation.