CVE-2020-0760 - CVE House
Back to Database
Status published High CVE-2020-0760

A remote code execution vulnerability exists when Microsoft Office improperly...

Vulnerability Description

A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0991.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-0760

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Microsoft Project, Microsoft Office, Office 365 ProPlus, Microsoft Excel, Microsoft PowerPoint, Microsoft Visio, Microsoft Word, Microsoft Publisher 2016 (32-bit edition), Microsoft Publisher 2016 (64-bit edition), Microsoft Access, Microsoft Outlook, Microsoft Publisher 2013 Service Pack 1 (32-bit editions), Microsoft Publisher 2013 Service Pack 1 (64-bit editions), Microsoft Publisher
Vulnerable Versions:
2013 Service Pack 1 (32-bit editions), 2013 Service Pack 1 (64-bit editions), 2016 (32-bit edition), 2016 (64-bit edition), 2010 Service Pack 2 (32-bit editions), 2010 Service Pack 2 (64-bit editions), 2019 for 32-bit editions, 2019 for 64-bit editions, 2013 RT Service Pack 1, 32-bit Systems, 64-bit Systems, unspecified

Timeline

Official Publish: April 15th, 2020
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.