KLA11663
Multiple vulnerabilities in Microsoft Office

Updated: 06/03/2020
Detect date
?
02/11/2020
Severity
?
High
Description

Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to execute arbitrary code, spoof user interface, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Microsoft Excel can be exploited remotely via specially crafted file to execute arbitrary code.
  2. A cross-site-scripting (XSS) vulnerability Microsoft Office SharePoint can be exploited remotely via specially crafted web to spoof user interface.
  3. A security feature bypass vulnerability in Microsoft Outlook can be exploited remotely via specially crafted to bypass security restrictions.
  4. A tampering vulnerability in Microsoft Office can be exploited remotely via specially crafted file to spoof user interface.
  5. A spoofing vulnerability in Microsoft Office Online Server can be exploited remotely via specially crafted request to spoof user interface.
Affected products

Microsoft Excel 2016 (32-bit edition)
Microsoft Outlook 2013 Service Pack 1 (32-bit editions)
Microsoft Excel 2016 (64-bit edition)
Microsoft Outlook 2010 Service Pack 2 (32-bit editions)
Microsoft Outlook 2013 Service Pack 1 (64-bit editions)
Office Online Server
Microsoft SharePoint Enterprise Server 2016
Microsoft SharePoint Server 2019
Microsoft Excel 2010 Service Pack 2 (32-bit editions)
Office 365 ProPlus for 32-bit Systems
Microsoft Outlook 2016 (64-bit edition)
Microsoft Excel 2010 Service Pack 2 (64-bit editions)
Office 365 ProPlus for 64-bit Systems
Microsoft SharePoint Server 2013 Service Pack 1
Microsoft Excel 2013 RT Service Pack 1
Microsoft Office 2019 for 64-bit editions
Microsoft Excel 2013 Service Pack 1 (64-bit editions)
Microsoft Office 2019 for 32-bit editions
Microsoft Excel 2013 Service Pack 1 (32-bit editions)
Microsoft Outlook 2010 Service Pack 2 (64-bit editions)
Microsoft Office 2019 for Mac
Microsoft Outlook 2016 (32-bit edition)
Microsoft Outlook 2013 RT Service Pack 1
Microsoft Office 2016 for Mac

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2020-0759
CVE-2020-0693
CVE-2020-0696
CVE-2020-0697
CVE-2020-0694
CVE-2020-0695

Impacts
?
ACE 
[?]

SB 
[?]

SUI 
[?]
Related products
Microsoft Office
Microsoft Outlook
Microsoft Excel
CVE-IDS
?
CVE-2020-07599.3Critical
CVE-2020-06933.5Warning
CVE-2020-06964.3Warning
CVE-2020-06977.2High
CVE-2020-06943.5Warning
CVE-2020-06955.8High
KB list

4484265
4484254
4484264
4484255
4484259
4484156
4484163
4484267
4484256
4484250

Microsoft official advisories
Microsoft Security Update Guide
Find out the statistics of the vulnerabilities spreading in your region