First published: Fri Oct 16 2020(Updated: )
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Remote Code Execution Vulnerability'.
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft 365 Apps | ||
Microsoft Office | =2010-sp2 | |
Microsoft Office | =2013-sp1 | |
Microsoft Office | =2013-sp1 | |
Microsoft Office | =2016 | |
Microsoft Office | =2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-16954 is rated as critical due to its potential for remote code execution in affected Microsoft Office applications.
To fix CVE-2020-16954, users should apply the latest security updates provided by Microsoft for their respective Office version.
CVE-2020-16954 affects Microsoft Office 2010 SP2, 2013 SP1, 2016, 2019, and Microsoft 365 Apps.
Exploiting CVE-2020-16954 could allow an attacker to execute arbitrary code on a vulnerable system.
At the time of its disclosure, CVE-2020-16954 was reported to be actively exploited in the wild.