CVE-2020-1581High
Microsoft Office Click-to-Run Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) components handle objects in memory. An attacker who successfully exploited the vulnerability could elevate privileges. The attacker would need to already have the ability to execute code on the system. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The security update addresses the vulnerability by correcting how Microsoft Office Click-to-Run (C2R) components handle objects in memory.
🎯 Affected products6
- Microsoft 365 Apps for Enterprise for 32-bit Systems
- Microsoft 365 Apps for Enterprise for 64-bit Systems
- Microsoft Office 2013 Click-to-Run (C2R) for 32-bit editions
- Microsoft Office 2013 Click-to-Run (C2R) for 64-bit editions
- Microsoft Office 2019 for 32-bit editions
- Microsoft Office 2019 for 64-bit editions
✅ Remediation
KBClick to Run (Security Update) — fixed build 15.0.5571.1000 KBClick to Run (Security Update) — fixed build https://aka.ms/OfficeSecurityReleases