KLA12002
Multiple vulnerabilities in Microsoft Office

Updated: 11/16/2020
Detect date
?
11/10/2020
Severity
?
High
Description

Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to obtain sensitive information, spoof user interface, execute arbitrary code, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. An information disclosure vulnerability in Microsoft SharePoint can be exploited remotely to obtain sensitive information.
  2. A spoofing vulnerability in Microsoft SharePoint can be exploited remotely to spoof user interface.
  3. A remote code execution vulnerability in Microsoft Excel can be exploited remotely to execute arbitrary code.
  4. A remote code execution vulnerability in Microsoft Office Access Connectivity Engine can be exploited remotely to execute arbitrary code.
  5. A spoofing vulnerability in Microsoft Office Online can be exploited remotely to spoof user interface.
  6. A remote code execution vulnerability in Microsoft SharePoint can be exploited remotely to execute arbitrary code.
  7. A security feature bypass vulnerability in Microsoft Excel can be exploited remotely to bypass security restrictions.
  8. A security feature bypass vulnerability in Microsoft Word can be exploited remotely to bypass security restrictions.
  9. A remote code execution vulnerability in Microsoft Teams can be exploited remotely to execute arbitrary code.
Affected products

Microsoft Excel 2016 (64-bit edition)
Microsoft Excel 2010 Service Pack 2 (64-bit editions)
Microsoft Office 2010 Service Pack 2 (64-bit editions)
Microsoft Office 2013 Service Pack 1 (32-bit editions)
Microsoft SharePoint Foundation 2010 Service Pack 2
Microsoft Excel 2013 Service Pack 1 (32-bit editions)
Microsoft Office Web Apps 2013 Service Pack 1
Microsoft SharePoint Foundation 2013 Service Pack 1
Microsoft Teams
Microsoft 365 Apps for Enterprise for 64-bit Systems
Microsoft Office 2010 Service Pack 2 (32-bit editions)
Microsoft Office 2019 for 64-bit editions
Microsoft Office 2019 for Mac
Microsoft Word 2016 (32-bit edition)
Microsoft Office 2013 Service Pack 1 (64-bit editions)
Microsoft Excel 2010 Service Pack 2 (32-bit editions)
Microsoft Office 2016 (32-bit edition)
Microsoft SharePoint Server 2019
Microsoft Word 2016 (64-bit edition)
Microsoft Word 2013 Service Pack 1 (64-bit editions)
Microsoft Word 2013 RT Service Pack 1
Microsoft Word 2013 Service Pack 1 (32-bit editions)
Microsoft SharePoint Enterprise Server 2016
Microsoft Office 2016 (64-bit edition)
Microsoft Excel 2016 (32-bit edition)
Microsoft 365 Apps for Enterprise for 32-bit Systems
Microsoft Excel 2013 Service Pack 1 (64-bit editions)
Microsoft SharePoint Enterprise Server 2013 Service Pack 1
Microsoft Excel 2013 RT Service Pack 1
Microsoft Word 2010 Service Pack 2 (32-bit editions)
Microsoft Office 2013 RT Service Pack 1
Microsoft SharePoint Server 2010 Service Pack 2
Microsoft Office 2019 for 32-bit editions
Microsoft Office Online Server
Microsoft Word 2010 Service Pack 2 (64-bit editions)

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2020-17017
CVE-2020-17016
CVE-2020-17019
CVE-2020-17015
CVE-2020-17062
CVE-2020-17063
CVE-2020-16979
CVE-2020-17060
CVE-2020-17061
CVE-2020-17067
CVE-2020-17064
CVE-2020-17065
CVE-2020-17066
CVE-2020-17020
CVE-2020-17091

Impacts
?
ACE 
[?]

OSI 
[?]

SB 
[?]

SUI 
[?]
Related products
Microsoft Office Access
Microsoft Office
Microsoft Excel
Microsoft Word
Microsoft Sharepoint Server
CVE-IDS
?
KB list

4486733
4486730
4486719
4486718
4486734
4486714
4486717
4486738
4486713
4486743
4484520
4484508
4486722
4486723
4486725
4486740
4486727
4486706
4484534
4486744
4486737
4484455

Find out the statistics of the vulnerabilities spreading in your region