Security restrictions bypass in Microsoft Excel - CVE-2020-17130

 

Security restrictions bypass in Microsoft Excel - CVE-2020-17130

Published: December 8, 2020


Vulnerability identifier: #VU48848
CSH Severity: Medium
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-17130
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to Microsoft Excel  does not properly impose security restrictions, which leads to security restrictions bypass.


Affected software

Microsoft Excel

How to mitigate CVE-2020-17130

Install updates from vendor's website.


External References

Related Security Bulletins