Input validation error in Microsoft Office - #VU27118

 

Input validation error in Microsoft Office - #VU27118

Published: April 22, 2020


Vulnerability identifier: #VU27118
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Microsoft
Affected software:
Microsoft Office

Detailed vulnerability description

The vulnerability allows a remote attacker to compromise the affected system

Multiple vulnerabilities exists due to improper input validation when processing 3D content within the Autodesk FBX library, used by Microsoft Office and Microsoft 3D Paint. A remote attacker can trick the victim into opening a specially crafted file, trigger memory corruption and execute arbitrary code on the target system.


Remediation

Install updates from vendor's website.

Sources