CVE Vulnerabilities

CVE-2020-1449

Origin Validation Error

Published: Jul 14, 2020 | Modified: Jul 24, 2020
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

A remote code execution vulnerability exists in Microsoft Project software when the software fails to check the source markup of a file, aka Microsoft Project Remote Code Execution Vulnerability.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

Name Vendor Start Version End Version
365_apps Microsoft - (including) - (including)
Office Microsoft 2010-sp2 (including) 2010-sp2 (including)
Office Microsoft 2013-sp1 (including) 2013-sp1 (including)
Office Microsoft 2019 (including) 2019 (including)
Project_2016 Microsoft - (including) - (including)

References