KLA11663
Multiple vulnerabilities in Microsoft Office
Обновлено: 13/03/2020
Дата обнаружения
11/02/2020
Уровень угрозы
High
Описание

Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to execute arbitrary code, spoof user interface, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Microsoft Excel can be exploited remotely via specially crafted file to execute arbitrary code.
  2. A cross-site-scripting (XSS) vulnerability Microsoft Office SharePoint can be exploited remotely via specially crafted web to spoof user interface.
  3. A security feature bypass vulnerability in Microsoft Outlook can be exploited remotely via specially crafted to bypass security restrictions.
  4. A tampering vulnerability in Microsoft Office can be exploited remotely via specially crafted file to spoof user interface.
  5. A spoofing vulnerability in Microsoft Office Online Server can be exploited remotely via specially crafted request to spoof user interface.
Пораженные продукты

Microsoft Excel 2016 (32-bit edition)
Microsoft Outlook 2013 Service Pack 1 (32-bit editions)
Microsoft Excel 2016 (64-bit edition)
Microsoft Outlook 2010 Service Pack 2 (32-bit editions)
Microsoft Outlook 2013 Service Pack 1 (64-bit editions)
Office Online Server
Microsoft SharePoint Enterprise Server 2016
Microsoft SharePoint Server 2019
Microsoft Excel 2010 Service Pack 2 (32-bit editions)
Office 365 ProPlus for 32-bit Systems
Microsoft Outlook 2016 (64-bit edition)
Microsoft Excel 2010 Service Pack 2 (64-bit editions)
Office 365 ProPlus for 64-bit Systems
Microsoft SharePoint Server 2013 Service Pack 1
Microsoft Excel 2013 RT Service Pack 1
Microsoft Office 2019 for 64-bit editions
Microsoft Excel 2013 Service Pack 1 (64-bit editions)
Microsoft Office 2019 for 32-bit editions
Microsoft Excel 2013 Service Pack 1 (32-bit editions)
Microsoft Outlook 2010 Service Pack 2 (64-bit editions)
Microsoft Office 2019 for Mac
Microsoft Outlook 2016 (32-bit edition)
Microsoft Outlook 2013 RT Service Pack 1
Microsoft Office 2016 for Mac

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2020-0759
CVE-2020-0693
CVE-2020-0696
CVE-2020-0697
CVE-2020-0694
CVE-2020-0695
Оказываемое влияние
?
ACE 
[?]

SB 
[?]

SUI 
[?]
Связанные продукты
Microsoft Office
Microsoft Outlook
Microsoft Excel
CVE-IDS
CVE-2020-07590.0Unknown
CVE-2020-06930.0Unknown
CVE-2020-06960.0Unknown
CVE-2020-06970.0Unknown
CVE-2020-06940.0Unknown
CVE-2020-06950.0Unknown
KB list

4484265
4484254
4484264
4484255
4484259
4484156
4484163
4484267
4484256
4484250

Microsoft official advisories
Microsoft Security Update Guide