#VU28924 Input validation error in Microsoft Word for Android


Published: 2020-06-10

Vulnerability identifier: #VU28924

Vulnerability risk: High

CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2020-1223

CWE-ID: CWE-20

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Microsoft Word for Android
Mobile applications / Apps for mobile phones

Vendor: Microsoft

Description

The vulnerability allows a remote attacker to compromise the affected device.

The vulnerability exists due to insufficient validation of user-supplied input when processing URLs. A remote attacker can trick the victim to open a specially crafted URL and execute arbitrary code in the system.

Successful exploitation of the vulnerability may result in full device compromise.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Microsoft Word for Android: 16.0.8730.2050 - 16.0.12730.20214


External links
http://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1223


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability