← All CVEs

CVE-2020-0892

high · 7.8

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0852, CVE-2020-0855.

7.8
CVSS
11.8%
EPSS (exploit prob.)
96th
EPSS percentile
2020-03-12
Published

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

VendorProductAffected versions
microsoftoffice2010
microsoftoffice2016
microsoftoffice2019
microsoftoffice2019
microsoftoffice_365_proplusall versions
microsoftoffice_online_server1.0
microsoftoffice_web_apps2010
microsoftsharepoint_enterprise_server2013
microsoftsharepoint_enterprise_server2016
microsoftsharepoint_foundation2013
microsoftsharepoint_server2010
microsoftsharepoint_server2019
microsoftword2010
microsoftword2013
microsoftword2013
microsoftword2016

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-0892