Input validation error in Microsoft Word for Android - CVE-2020-1223

 

Input validation error in Microsoft Word for Android - CVE-2020-1223

Published: June 10, 2020


Vulnerability identifier: #VU28924
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1223
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected device.

The vulnerability exists due to insufficient validation of user-supplied input when processing URLs. A remote attacker can trick the victim to open a specially crafted URL and execute arbitrary code in the system.

Successful exploitation of the vulnerability may result in full device compromise.


Affected software

Microsoft Word for Android

How to mitigate CVE-2020-1223

Install updates from vendor's website.

Microsoft Word for Android - update to 16.0.12827.20140

External References

Related Security Bulletins