CVE-2020-1583: Microsoft Word Information Disclosure Vulnerability
An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory, aka 'Microsoft Word Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1502, CVE-2020-1503.
Other sources
An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker must know the memory address location where the object was created. The update addresses the vulnerability by changing the way certain Word functions handle objects in memory.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-1583?
CVE-2020-1583 is an information disclosure vulnerability in Microsoft Word.
What is the severity of CVE-2020-1583?
The severity of CVE-2020-1583 is medium (5.5).
Which software versions are affected by CVE-2020-1583?
Microsoft Office LTSC for Mac 2021, Microsoft Office 2010 SP2, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office Online Server, Microsoft Office Web Apps, Microsoft SharePoint Enterprise Server, Microsoft SharePoint Server, and Microsoft Word 2010 SP2, 2013 SP1, and 2016 are affected by CVE-2020-1583.
How does CVE-2020-1583 occur?
CVE-2020-1583 occurs when Microsoft Word improperly discloses the contents of its memory.
Where can I find more information about CVE-2020-1583?
You can find more information about CVE-2020-1583 at the following link: [CVE-2020-1583 Advisory](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1583)