KLA12023
Multiple vulnerabilities in Microsoft Office

Updated: 12/10/2020
Detect date
?
12/08/2020
Severity
?
Critical
Description

Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to execute arbitrary code, spoof user interface, obtain sensitive information, bypass security restrictions, gain privileges.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Microsoft Excel can be exploited remotely to execute arbitrary code.
  2. A spoofing vulnerability in Microsoft SharePoint can be exploited remotely to spoof user interface.
  3. A remote code execution vulnerability in Microsoft SharePoint can be exploited remotely to execute arbitrary code.
  4. An information disclosure vulnerability in Microsoft SharePoint can be exploited remotely to obtain sensitive information.
  5. A security feature bypass vulnerability in Microsoft Excel can be exploited remotely to bypass security restrictions.
  6. An information disclosure vulnerability in Microsoft Excel can be exploited remotely to obtain sensitive information.
  7. A remote code execution vulnerability in Microsoft PowerPoint can be exploited remotely to execute arbitrary code.
  8. An elevation of privilege vulnerability in Microsoft SharePoint can be exploited remotely to gain privileges.
  9. An information disclosure vulnerability in Microsoft Outlook can be exploited remotely to obtain sensitive information.
Affected products

Microsoft SharePoint Server 2019
Microsoft PowerPoint 2016 (32-bit edition)
Microsoft Excel 2010 Service Pack 2 (32-bit editions)
Microsoft PowerPoint 2013 Service Pack 1 (32-bit editions)
Microsoft Excel 2016 (64-bit edition)
Office Online Server
Microsoft Office 2019 for Mac
Microsoft Excel 2013 Service Pack 1 (64-bit editions)
Microsoft Office 2016 (32-bit edition)
Microsoft Office 2019 for 64-bit editions
Microsoft Excel 2013 RT Service Pack 1
Microsoft SharePoint Enterprise Server 2016
Microsoft Outlook 2013 Service Pack 1 (32-bit editions)
Microsoft Office 2010 Service Pack 2 (64-bit editions)
Microsoft PowerPoint 2016 (64-bit edition)
Microsoft Excel 2010 Service Pack 2 (64-bit editions)
Microsoft Outlook 2010 Service Pack 2 (32-bit editions)
Microsoft Office 2019 for 32-bit editions
Microsoft Office 2016 (64-bit edition)
Microsoft Outlook 2010 Service Pack 2 (64-bit editions)
Microsoft PowerPoint 2010 Service Pack 2 (64-bit editions)
Microsoft SharePoint Foundation 2010 Service Pack 2
Microsoft Office 2010 Service Pack 2 (32-bit editions)
Microsoft SharePoint Server 2010 Service Pack 2
Microsoft Outlook 2013 Service Pack 1 (64-bit editions)
Microsoft PowerPoint 2013 RT Service Pack 1
Microsoft Office Web Apps 2010 Service Pack 2
Microsoft Office Web Apps 2013 Service Pack 1
Microsoft Excel 2013 Service Pack 1 (32-bit editions)
Microsoft SharePoint Foundation 2013 Service Pack 1
Microsoft 365 Apps for Enterprise for 64-bit Systems
Microsoft Excel 2016 (32-bit edition)
Microsoft 365 Apps for Enterprise for 32-bit Systems
Microsoft PowerPoint 2013 Service Pack 1 (64-bit editions)
Microsoft PowerPoint 2010 Service Pack 2 (32-bit editions)
Microsoft Office Online Server
Microsoft Outlook 2016 (64-bit edition)
Microsoft Outlook 2013 RT Service Pack 1
Microsoft Outlook 2016 (32-bit edition)

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2020-17129
CVE-2020-17128
CVE-2020-17115
CVE-2020-17123
CVE-2020-17122
CVE-2020-17121
CVE-2020-17120
CVE-2020-17130
CVE-2020-17126
CVE-2020-17125
CVE-2020-17124
CVE-2020-17127
CVE-2020-17089
CVE-2020-17118
CVE-2020-17119

Impacts
?
ACE 
[?]

OSI 
[?]

SB 
[?]

PE 
[?]

SUI 
[?]
Related products
Microsoft Office
Microsoft Outlook
Microsoft Excel
CVE-IDS
?
CVE-2020-171290.0Unknown
CVE-2020-171280.0Unknown
CVE-2020-171150.0Unknown
CVE-2020-171230.0Unknown
CVE-2020-171220.0Unknown
CVE-2020-171210.0Unknown
CVE-2020-171200.0Unknown
CVE-2020-171300.0Unknown
CVE-2020-171260.0Unknown
CVE-2020-171250.0Unknown
CVE-2020-171240.0Unknown
CVE-2020-171270.0Unknown
CVE-2020-170890.0Unknown
CVE-2020-171180.0Unknown
CVE-2020-171190.0Unknown
KB list

4493139
4493138
4486732
4484468
4484372
4484393
4486750
4486753
4486752
4486754
4486757
4486698
4493140
4486748
4493148
4493149
4486696
4486697
4486721
4486742
4486704
4486760
4486751