CVE-2020-16933
vulnerability analysis and mitigation

Overview

A security feature bypass vulnerability (CVE-2020-16933) was discovered in Microsoft Word software that fails to properly handle .LNK files. The vulnerability was disclosed on October 13, 2020, affecting Microsoft Word 2016 and other versions of the software (CVE Details).

Technical details

The vulnerability exists when Microsoft Word software fails to properly handle .LNK files, allowing potential security feature bypass. The issue requires user interaction and could enable an attacker to perform actions in the security context of the current user (MITRE CVE).

Impact

If successfully exploited, this vulnerability could allow an attacker to perform actions with the same permissions as the logged-on user. The attacker could use a specially crafted file to take actions on behalf of the current user within their permission level (MITRE CVE).

Exploitability

The exploitation requires user interaction. An attacker could exploit this vulnerability through email-based attacks by sending specially crafted files to targets or through web-based scenarios by hosting malicious content. The attacker would need to convince users to open specially crafted files with an affected version of Microsoft Word (MITRE CVE).

Mitigation and workarounds

Microsoft released security update 4486679 to address this vulnerability. The update is available through Microsoft Update, Microsoft Update Catalog, and Microsoft Download Center for both 32-bit and 64-bit versions of Word 2016. The security update addresses the vulnerability by correcting how Microsoft Word handles .LNK files (Microsoft Support).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management