KLA12023
Multiple vulnerabilities in Microsoft Office

Обновлено: 16/02/2021
Дата обнаружения
08/12/2020
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to execute arbitrary code, spoof user interface, obtain sensitive information, bypass security restrictions, gain privileges.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Microsoft Excel can be exploited remotely to execute arbitrary code.
  2. A spoofing vulnerability in Microsoft SharePoint can be exploited remotely to spoof user interface.
  3. A remote code execution vulnerability in Microsoft SharePoint can be exploited remotely to execute arbitrary code.
  4. An information disclosure vulnerability in Microsoft SharePoint can be exploited remotely to obtain sensitive information.
  5. A security feature bypass vulnerability in Microsoft Excel can be exploited remotely to bypass security restrictions.
  6. An information disclosure vulnerability in Microsoft Excel can be exploited remotely to obtain sensitive information.
  7. A remote code execution vulnerability in Microsoft PowerPoint can be exploited remotely to execute arbitrary code.
  8. An elevation of privilege vulnerability in Microsoft SharePoint can be exploited remotely to gain privileges.
  9. An information disclosure vulnerability in Microsoft Outlook can be exploited remotely to obtain sensitive information.
Эксплуатация

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Пораженные продукты

Microsoft SharePoint Server 2019
Microsoft PowerPoint 2016 (32-bit edition)
Microsoft Excel 2010 Service Pack 2 (32-bit editions)
Microsoft PowerPoint 2013 Service Pack 1 (32-bit editions)
Microsoft Excel 2016 (64-bit edition)
Office Online Server
Microsoft Office 2019 for Mac
Microsoft Excel 2013 Service Pack 1 (64-bit editions)
Microsoft Office 2016 (32-bit edition)
Microsoft Office 2019 for 64-bit editions
Microsoft Excel 2013 RT Service Pack 1
Microsoft SharePoint Enterprise Server 2016
Microsoft Outlook 2013 Service Pack 1 (32-bit editions)
Microsoft Office 2010 Service Pack 2 (64-bit editions)
Microsoft PowerPoint 2016 (64-bit edition)
Microsoft Excel 2010 Service Pack 2 (64-bit editions)
Microsoft Outlook 2010 Service Pack 2 (32-bit editions)
Microsoft Office 2019 for 32-bit editions
Microsoft Office 2016 (64-bit edition)
Microsoft Outlook 2010 Service Pack 2 (64-bit editions)
Microsoft PowerPoint 2010 Service Pack 2 (64-bit editions)
Microsoft SharePoint Foundation 2010 Service Pack 2
Microsoft Office 2010 Service Pack 2 (32-bit editions)
Microsoft SharePoint Server 2010 Service Pack 2
Microsoft Outlook 2013 Service Pack 1 (64-bit editions)
Microsoft PowerPoint 2013 RT Service Pack 1
Microsoft Office Web Apps 2010 Service Pack 2
Microsoft Office Web Apps 2013 Service Pack 1
Microsoft Excel 2013 Service Pack 1 (32-bit editions)
Microsoft SharePoint Foundation 2013 Service Pack 1
Microsoft 365 Apps for Enterprise for 64-bit Systems
Microsoft Excel 2016 (32-bit edition)
Microsoft 365 Apps for Enterprise for 32-bit Systems
Microsoft PowerPoint 2013 Service Pack 1 (64-bit editions)
Microsoft PowerPoint 2010 Service Pack 2 (32-bit editions)
Microsoft Office Online Server
Microsoft Outlook 2016 (64-bit edition)
Microsoft Outlook 2013 RT Service Pack 1
Microsoft Outlook 2016 (32-bit edition)

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2020-17129
CVE-2020-17128
CVE-2020-17115
CVE-2020-17123
CVE-2020-17122
CVE-2020-17121
CVE-2020-17120
CVE-2020-17130
CVE-2020-17126
CVE-2020-17125
CVE-2020-17124
CVE-2020-17127
CVE-2020-17089
CVE-2020-17118
CVE-2020-17119
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

SB 
[?]

PE 
[?]

SUI 
[?]
Связанные продукты
Microsoft Office
Microsoft Outlook
Microsoft Excel
CVE-IDS
CVE-2020-171299.3Critical
CVE-2020-171289.3Critical
CVE-2020-171156.0High
CVE-2020-171239.3Critical
CVE-2020-171229.3Critical
CVE-2020-171216.5High
CVE-2020-171204.0Warning
CVE-2020-171306.0High
CVE-2020-171262.1Warning
CVE-2020-171259.3Critical
CVE-2020-171249.3Critical
CVE-2020-171279.3Critical
CVE-2020-170896.0High
CVE-2020-171195.0Critical
KB list

4493139
4493138
4486732
4484468
4484372
4484393
4486750
4486753
4486752
4486754
4486757
4486698
4493140
4486748
4493148
4493149
4486696
4486697
4486721
4486742
4486704
4486760
4486751