Input validation error in Microsoft Office - #VU27118

 

Input validation error in Microsoft Office - #VU27118

Published: April 22, 2020


Vulnerability identifier: #VU27118
CSH Severity: High
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Microsoft Office
Software vendor:
Microsoft

Description

The vulnerability allows a remote attacker to compromise the affected system

Multiple vulnerabilities exists due to improper input validation when processing 3D content within the Autodesk FBX library, used by Microsoft Office and Microsoft 3D Paint. A remote attacker can trick the victim into opening a specially crafted file, trigger memory corruption and execute arbitrary code on the target system.


Remediation

Install updates from vendor's website.

External links