Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2020-1223

Опубликовано: 09 июн. 2020
Источник: msrc
EPSS Средний

Описание

Word for Android Remote Code Execution Vulnerability

A remote code execution vulnerability exists when Microsoft Word for Android fails to properly handle certain files.

To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file.

The update addresses the vulnerability by correcting how Microsoft Word for Android handles specially crafted URL files.

FAQ

How do I get the update for Microsoft Word for Android?

  1. Tap the Google Play icon on your home screen.
  2. Swipe in from the left edge of the screen.
  3. Tap My apps & games.
  4. Tap the Update box next to the Microsoft Word app.

Is there a direct link on the web?

Yes: https://play.google.com/store/apps/details?id=com.microsoft.office.word&hl=en_US

Обновления

ПродуктСтатьяОбновление
Microsoft Word for Android

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

N/A

DOS

N/A

EPSS

Процентиль: 97%
0.36771
Средний

Связанные уязвимости

CVSS3: 8.8
nvd
больше 5 лет назад

A remote code execution vulnerability exists when Microsoft Word for Android fails to properly handle certain files.To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file.The update addresses the vulnerability by correcting how Microsoft Word for Android handles specially crafted URL files., aka 'Word for Android Remote Code Execution Vulnerability'.

github
больше 3 лет назад

A remote code execution vulnerability exists when Microsoft Word for Android fails to properly handle certain files.To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file.The update addresses the vulnerability by correcting how Microsoft Word for Android handles specially crafted URL files., aka 'Word for Android Remote Code Execution Vulnerability'.

CVSS3: 8.8
fstec
больше 5 лет назад

Уязвимость текстового редактора Microsoft Word for Android, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 97%
0.36771
Средний