A remote code execution vulnerability exists in Microsoft Project software when the software fails to check the source markup of a file, aka 'Microsoft Project Remote Code Execution Vulnerability'.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Microsoft Office | office-click-to-run-upgrade-latest | Aug 13, 2020 | Jul 14, 2020 | |
| Msft | — | msft-kb4484450-01fe227d-9734-4646-acfd-05ffca051ff3msft-kb4484450-f3ec1af2-69e9-47b4-afe9-b9efe8f969d9msft-kb4484463-a7ec31c2-116e-4004-9b21-77562a56c67amsft-kb4484463-a9fe1769-5693-4f61-b95b-746458724e3f | Jul 14, 2020 | Jul 14, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub