
Cloud Vulnerability DB
A community-led vulnerabilities database
A remote code execution vulnerability (CVE-2020-16930) was discovered in Microsoft Excel that exists when the software fails to properly handle objects in memory. The vulnerability was disclosed and patched on October 13, 2020, affecting various versions of Microsoft Office 2016 including Professional Plus, Professional, Standard, Home and Business, and Home and Student editions (Microsoft Support).
The vulnerability specifically exists within the parsing of XLS files and results from the lack of proper initialization of a pointer prior to accessing it, as well as improper validation of user-supplied data which can result in a write past the end of an allocated buffer. The vulnerability has been assigned a CVSS score of 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) (ZDI Advisory).
If successfully exploited, this vulnerability allows attackers to execute arbitrary code in the context of the current process on affected installations of Microsoft Excel. The attack requires user interaction, specifically the target must open a malicious file or visit a malicious page (ZDI Advisory).
The vulnerability requires user interaction to be exploited, where the target must either visit a malicious page or open a malicious file. The specific attack vector involves manipulating XLS files to trigger the vulnerability (ZDI Advisory).
Microsoft has released security update 4484417 to address this vulnerability. The update is available through Microsoft Update, Microsoft Update Catalog, and Microsoft Download Center. For the 32-bit and 64-bit versions of Office 2016, specific security updates have been made available (Microsoft Support).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."