CVE-2020-16957HighCVSS 7.8

Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

Published
October 13, 2020
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Microsoft Office Access Connectivity Engine handles objects in memory.

🎯 Affected products4

  • Microsoft 365 Apps for Enterprise for 32-bit Systems
  • Microsoft 365 Apps for Enterprise for 64-bit Systems
  • Microsoft Office 2019 for 32-bit editions
  • Microsoft Office 2019 for 64-bit editions

✅ Remediation

KBClick to Run (Security Update)

🔗 References (1)