CVE-2020-1497: Microsoft Excel Information Disclosure Vulnerability
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.
Other sources
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker must know the memory address location where the object was created. The update addresses the vulnerability by changing the way certain Excel functions handle objects in memory.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1497?
CVE-2020-1497 has a severity rating of important.
How do I fix CVE-2020-1497?
To fix CVE-2020-1497, ensure that you install the latest updates for Microsoft Excel and Microsoft Office.
What are the affected versions for CVE-2020-1497?
CVE-2020-1497 affects Microsoft Excel 2010, 2013, 2016, and 2019, as well as Microsoft 365 Apps.
What type of vulnerability is CVE-2020-1497?
CVE-2020-1497 is classified as an information disclosure vulnerability.
Can CVE-2020-1497 be exploited remotely?
Yes, CVE-2020-1497 can potentially be exploited by an attacker to gain unauthorized access to sensitive information.