KLA11774
Multiple vulnerabilities in Microsoft Office
Обновлено: 29/05/2020
Дата обнаружения
12/05/2020
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to spoof user interface, execute arbitrary code, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A cross-site-scripting (XSS) vulnerability Microsoft Office SharePoint can be exploited remotely via specially crafted web to spoof user interface.
  2. A remote code execution vulnerability in Microsoft Excel can be exploited remotely via specially crafted file to execute arbitrary code.
  3. A remote code execution vulnerability in Microsoft SharePoint Server can be exploited remotely via specially crafted page to execute arbitrary code.
  4. A remote code execution vulnerability in Microsoft SharePoint can be exploited remotely via specially crafted to execute arbitrary code.
  5. An information disclosure vulnerability in Microsoft SharePoint can be exploited remotely to obtain sensitive information.
  6. A spoofing vulnerability in Microsoft SharePoint can be exploited remotely via specially crafted web to spoof user interface.
Пораженные продукты

Microsoft Excel 2010 Service Pack 2 (64-bit editions)
Microsoft Office 2019 for 32-bit editions
Microsoft Office 2019 for 64-bit editions
Microsoft Excel 2016 (64-bit edition)
Microsoft Office 2016 for Mac
Microsoft Excel 2010 Service Pack 2 (32-bit editions)
Microsoft Excel 2013 RT Service Pack 1
Microsoft Excel 2013 Service Pack 1 (64-bit editions)
Microsoft SharePoint Foundation 2013 Service Pack 1
Microsoft SharePoint Server 2019
Microsoft 365 Apps for Enterprise for 64-bit Systems
Microsoft Excel 2016 (32-bit edition)
Microsoft Excel 2013 Service Pack 1 (32-bit editions)
Microsoft SharePoint Enterprise Server 2013 Service Pack 1
Microsoft SharePoint Enterprise Server 2016
Microsoft SharePoint Server 2010 Service Pack 2
Microsoft Office 2019 for Mac
Microsoft 365 Apps for Enterprise for 32-bit Systems

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2020-1099
CVE-2020-0901
CVE-2020-1069
CVE-2020-1024
CVE-2020-1100
CVE-2020-1101
CVE-2020-1023
CVE-2020-1103
CVE-2020-1102
CVE-2020-1105
CVE-2020-1104
CVE-2020-1107
CVE-2020-1106
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

SUI 
[?]
Связанные продукты
Microsoft Office
Microsoft Excel
CVE-IDS
CVE-2020-10990.0Unknown
CVE-2020-09010.0Unknown
CVE-2020-10690.0Unknown
CVE-2020-10240.0Unknown
CVE-2020-11000.0Unknown
CVE-2020-11010.0Unknown
CVE-2020-10230.0Unknown
CVE-2020-11030.0Unknown
CVE-2020-11020.0Unknown
CVE-2020-11050.0Unknown
CVE-2020-11040.0Unknown
CVE-2020-11070.0Unknown
CVE-2020-11060.0Unknown
KB list

4484364
4484383
4484338
4484336
4484384
4484332
4484365
4484352

Microsoft official advisories
Microsoft Security Update Guide