KLA11932
Multiple vulnerabilities in Microsoft Office

Обновлено: 18/08/2020
Дата обнаружения
11/08/2020
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to obtain sensitive information, spoof user interface, execute arbitrary code, gain privileges.

Below is a complete list of vulnerabilities:

  1. An information disclosure vulnerability in Microsoft Outlook can be exploited remotely to obtain sensitive information.
  2. A cross-site-scripting (XSS) vulnerability Microsoft Office SharePoint can be exploited remotely via specially crafted web to spoof user interface.
  3. An information disclosure vulnerability in Microsoft Excel can be exploited remotely to obtain sensitive information.
  4. An information disclosure vulnerability in Microsoft Word can be exploited remotely to obtain sensitive information.
  5. A remote code execution vulnerability in Microsoft Excel can be exploited remotely via specially crafted file to execute arbitrary code.
  6. A spoofing vulnerability in Microsoft SharePoint can be exploited remotely via specially crafted web to spoof user interface.
  7. A remote code execution vulnerability in Microsoft Office can be exploited remotely via specially crafted file to execute arbitrary code.
  8. A memory corruption vulnerability in Microsoft Outlook can be exploited remotely via specially crafted file to execute arbitrary code.
  9. A remote code execution vulnerability in Microsoft Access can be exploited remotely via specially crafted file to execute arbitrary code.
  10. An information disclosure vulnerability in Microsoft SharePoint can be exploited remotely via specially crafted application to obtain sensitive information.
  11. An elevation of privilege vulnerability in Microsoft Office Click-to-Run can be exploited remotely via specially crafted application to gain privileges.
Пораженные продукты

Microsoft SharePoint Server 2010 Service Pack 2
Microsoft Outlook 2016 (32-bit edition)
Microsoft Access 2010 Service Pack 2 (64-bit editions)
Microsoft Office 2016 (64-bit edition)
Microsoft Office 2010 Service Pack 2 (64-bit editions)
Microsoft Office Web Apps 2010 Service Pack 2
Office Online Server
Microsoft Office 2019 for 32-bit editions
Microsoft 365 Apps for Enterprise for 64-bit Systems
Microsoft SharePoint Enterprise Server 2013 Service Pack 1
Microsoft Office 2013 Click-to-Run (C2R) for 64-bit editions
Microsoft Excel 2013 RT Service Pack 1
Microsoft Outlook 2016 (64-bit edition)
Microsoft Outlook 2010 Service Pack 2 (64-bit editions)
Microsoft Office Online Server
Microsoft Word 2016 (64-bit edition)
Microsoft Outlook 2010 Service Pack 2 (32-bit editions)
Microsoft Word 2013 Service Pack 1 (64-bit editions)
Microsoft Access 2013 Service Pack 1 (32-bit editions)
Microsoft Office 2013 Click-to-Run (C2R) for 32-bit editions
Microsoft SharePoint Foundation 2010 Service Pack 2
Microsoft Word 2010 Service Pack 2 (32-bit editions)
Microsoft Word 2013 Service Pack 1 (32-bit editions)
Microsoft Office 2013 RT Service Pack 1
Microsoft Excel 2013 Service Pack 1 (64-bit editions)
Microsoft Access 2016 (32-bit edition)
Microsoft Outlook 2013 Service Pack 1 (32-bit editions)
Microsoft Word 2016 (32-bit edition)
Microsoft Office 2019 for 64-bit editions
Microsoft SharePoint Foundation 2013 Service Pack 1
Microsoft Office 2016 (32-bit edition)
Microsoft Office Web Apps 2013 Service Pack 1
Microsoft SharePoint Server 2019
Microsoft Excel 2010 Service Pack 2 (64-bit editions)
Microsoft Office 2010 Service Pack 2 (32-bit editions)
Microsoft Office 2016 for Mac
Microsoft Excel 2013 Service Pack 1 (32-bit editions)
Microsoft Outlook 2013 RT Service Pack 1
Microsoft Office 2019 for Mac
Microsoft Access 2016 (64-bit edition)
Microsoft Outlook 2013 Service Pack 1 (64-bit editions)
Microsoft Excel 2016 (32-bit edition)
Microsoft SharePoint Enterprise Server 2016
Microsoft 365 Apps for Enterprise for 32-bit Systems
Microsoft Office 2013 Service Pack 1 (64-bit editions)
Microsoft Access 2010 Service Pack 2 (32-bit editions)
Microsoft Office 2013 Service Pack 1 (32-bit editions)
Microsoft Word 2010 Service Pack 2 (64-bit editions)
Microsoft Word 2013 RT Service Pack 1
Microsoft Excel 2010 Service Pack 2 (32-bit editions)
Microsoft Excel 2016 (64-bit edition)
Microsoft Access 2013 Service Pack 1 (64-bit editions)

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2020-1493
CVE-2020-1573
CVE-2020-1497
CVE-2020-1583
CVE-2020-1495
CVE-2020-1494
CVE-2020-1499
CVE-2020-1498
CVE-2020-1563
CVE-2020-1483
CVE-2020-1582
CVE-2020-1580
CVE-2020-1505
CVE-2020-1581
CVE-2020-1504
CVE-2020-1502
CVE-2020-1501
CVE-2020-1500
CVE-2020-1503
CVE-2020-1496
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

PE 
[?]

SUI 
[?]
Связанные продукты
Microsoft Access
Microsoft Office
Microsoft Outlook
Microsoft Excel
Microsoft Word
CVE-IDS
CVE-2020-14934.3Warning
CVE-2020-15733.5Warning
CVE-2020-14974.3Warning
CVE-2020-15834.3Warning
CVE-2020-14959.3Critical
CVE-2020-14949.3Critical
CVE-2020-14995.5High
CVE-2020-14989.3Critical
CVE-2020-15639.3Critical
CVE-2020-14839.3Critical
CVE-2020-15826.8High
CVE-2020-15803.5Warning
CVE-2020-15052.1Warning
CVE-2020-15819.3Critical
CVE-2020-15049.3Critical
CVE-2020-15024.3Warning
CVE-2020-15015.5High
CVE-2020-15005.5High
CVE-2020-15034.3Warning
CVE-2020-14969.3Critical
KB list

4484476
4484191
4484379
4484359
4484465
4484449
4484354
4484461
4484470
4484462
4484375
4484487
4484486
4484484
4484481
4484366
4484183
4484478
4484479
4484431
4484472
4484473
4484346
4484471
4484340
4484474
4484475
4484385
4484494
4484495
4484497
4484490
4484492
4484498