← All CVEs

CVE-2020-1447

high · 8.8

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1448.

8.8
CVSS
10.6%
EPSS (exploit prob.)
96th
EPSS percentile
2020-07-14
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

VendorProductAffected versions
microsoft365_appsall versions
microsoftoffice2010
microsoftoffice2016
microsoftoffice2019
microsoftoffice2019
microsoftoffice_online_server1.0
microsoftoffice_web_apps2010
microsoftoffice_web_apps2013
microsoftsharepoint_enterprise_server2013
microsoftsharepoint_enterprise_server2016
microsoftsharepoint_server2010
microsoftsharepoint_server2019
microsoftword2010
microsoftword2013
microsoftword2016
microsoftword_rt2013

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-1447