KLA11774
Multiple vulnerabilities in Microsoft Office

Updated: 06/03/2020
Detect date
?
05/12/2020
Severity
?
Critical
Description

Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to spoof user interface, execute arbitrary code, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A cross-site-scripting (XSS) vulnerability Microsoft Office SharePoint can be exploited remotely via specially crafted web to spoof user interface.
  2. A remote code execution vulnerability in Microsoft Excel can be exploited remotely via specially crafted file to execute arbitrary code.
  3. A remote code execution vulnerability in Microsoft SharePoint Server can be exploited remotely via specially crafted page to execute arbitrary code.
  4. A remote code execution vulnerability in Microsoft SharePoint can be exploited remotely via specially crafted to execute arbitrary code.
  5. An information disclosure vulnerability in Microsoft SharePoint can be exploited remotely to obtain sensitive information.
  6. A spoofing vulnerability in Microsoft SharePoint can be exploited remotely via specially crafted web to spoof user interface.
Affected products

Microsoft Excel 2010 Service Pack 2 (64-bit editions)
Microsoft Office 2019 for 32-bit editions
Microsoft Office 2019 for 64-bit editions
Microsoft Excel 2016 (64-bit edition)
Microsoft Office 2016 for Mac
Microsoft Excel 2010 Service Pack 2 (32-bit editions)
Microsoft Excel 2013 RT Service Pack 1
Microsoft Excel 2013 Service Pack 1 (64-bit editions)
Microsoft SharePoint Foundation 2013 Service Pack 1
Microsoft SharePoint Server 2019
Microsoft 365 Apps for Enterprise for 64-bit Systems
Microsoft Excel 2016 (32-bit edition)
Microsoft Excel 2013 Service Pack 1 (32-bit editions)
Microsoft SharePoint Enterprise Server 2013 Service Pack 1
Microsoft SharePoint Enterprise Server 2016
Microsoft SharePoint Server 2010 Service Pack 2
Microsoft Office 2019 for Mac
Microsoft 365 Apps for Enterprise for 32-bit Systems

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2020-1099
CVE-2020-0901
CVE-2020-1069
CVE-2020-1024
CVE-2020-1100
CVE-2020-1101
CVE-2020-1023
CVE-2020-1103
CVE-2020-1102
CVE-2020-1105
CVE-2020-1104
CVE-2020-1107
CVE-2020-1106

Impacts
?
ACE 
[?]

OSI 
[?]

SUI 
[?]
Related products
Microsoft Office
Microsoft Excel
CVE-IDS
?
CVE-2020-10993.5Warning
CVE-2020-09017.5Critical
CVE-2020-10696.5High
CVE-2020-10246.5High
CVE-2020-11003.5Warning
CVE-2020-11013.5Warning
CVE-2020-10236.5High
CVE-2020-11034.3Warning
CVE-2020-11026.5High
CVE-2020-11053.5Warning
CVE-2020-11043.5Warning
CVE-2020-11073.5Warning
CVE-2020-11064.3Warning
KB list

4484364
4484383
4484338
4484336
4484384
4484332
4484365
4484352

Microsoft official advisories
Microsoft Security Update Guide
Find out the statistics of the vulnerabilities spreading in your region