KLA12002
Multiple vulnerabilities in Microsoft Office

Обновлено: 16/11/2020
Дата обнаружения
10/11/2020
Уровень угрозы
High
Описание

Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to obtain sensitive information, spoof user interface, execute arbitrary code, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. An information disclosure vulnerability in Microsoft SharePoint can be exploited remotely to obtain sensitive information.
  2. A spoofing vulnerability in Microsoft SharePoint can be exploited remotely to spoof user interface.
  3. A remote code execution vulnerability in Microsoft Excel can be exploited remotely to execute arbitrary code.
  4. A remote code execution vulnerability in Microsoft Office Access Connectivity Engine can be exploited remotely to execute arbitrary code.
  5. A spoofing vulnerability in Microsoft Office Online can be exploited remotely to spoof user interface.
  6. A remote code execution vulnerability in Microsoft SharePoint can be exploited remotely to execute arbitrary code.
  7. A security feature bypass vulnerability in Microsoft Excel can be exploited remotely to bypass security restrictions.
  8. A security feature bypass vulnerability in Microsoft Word can be exploited remotely to bypass security restrictions.
  9. A remote code execution vulnerability in Microsoft Teams can be exploited remotely to execute arbitrary code.
Пораженные продукты

Microsoft Excel 2016 (64-bit edition)
Microsoft Excel 2010 Service Pack 2 (64-bit editions)
Microsoft Office 2010 Service Pack 2 (64-bit editions)
Microsoft Office 2013 Service Pack 1 (32-bit editions)
Microsoft SharePoint Foundation 2010 Service Pack 2
Microsoft Excel 2013 Service Pack 1 (32-bit editions)
Microsoft Office Web Apps 2013 Service Pack 1
Microsoft SharePoint Foundation 2013 Service Pack 1
Microsoft Teams
Microsoft 365 Apps for Enterprise for 64-bit Systems
Microsoft Office 2010 Service Pack 2 (32-bit editions)
Microsoft Office 2019 for 64-bit editions
Microsoft Office 2019 for Mac
Microsoft Word 2016 (32-bit edition)
Microsoft Office 2013 Service Pack 1 (64-bit editions)
Microsoft Excel 2010 Service Pack 2 (32-bit editions)
Microsoft Office 2016 (32-bit edition)
Microsoft SharePoint Server 2019
Microsoft Word 2016 (64-bit edition)
Microsoft Word 2013 Service Pack 1 (64-bit editions)
Microsoft Word 2013 RT Service Pack 1
Microsoft Word 2013 Service Pack 1 (32-bit editions)
Microsoft SharePoint Enterprise Server 2016
Microsoft Office 2016 (64-bit edition)
Microsoft Excel 2016 (32-bit edition)
Microsoft 365 Apps for Enterprise for 32-bit Systems
Microsoft Excel 2013 Service Pack 1 (64-bit editions)
Microsoft SharePoint Enterprise Server 2013 Service Pack 1
Microsoft Excel 2013 RT Service Pack 1
Microsoft Word 2010 Service Pack 2 (32-bit editions)
Microsoft Office 2013 RT Service Pack 1
Microsoft SharePoint Server 2010 Service Pack 2
Microsoft Office 2019 for 32-bit editions
Microsoft Office Online Server
Microsoft Word 2010 Service Pack 2 (64-bit editions)

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2020-17017
CVE-2020-17016
CVE-2020-17019
CVE-2020-17015
CVE-2020-17062
CVE-2020-17063
CVE-2020-16979
CVE-2020-17060
CVE-2020-17061
CVE-2020-17067
CVE-2020-17064
CVE-2020-17065
CVE-2020-17066
CVE-2020-17020
CVE-2020-17091
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

SB 
[?]

SUI 
[?]
Связанные продукты
Microsoft Office Access
Microsoft Office
Microsoft Excel
Microsoft Word
Microsoft Sharepoint Server
CVE-IDS