CVE-2020-1223: Word for Android Remote Code Execution Vulnerability

Overview

Severity
N/A
Category
Remote Code Execution
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2020-Jun
Released
2020-06-09
EPSS Score
36.77% (percentile: 97.1%)

Description

A remote code execution vulnerability exists when Microsoft Word for Android fails to properly handle certain files. To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file. The update addresses the vulnerability by correcting how Microsoft Word for Android handles specially crafted URL files.

FAQ

How do I get the update for Microsoft Word for Android? Tap the Google Play icon on your home screen. Swipe in from the left edge of the screen. Tap My apps & games. Tap the Update box next to the Microsoft Word app. Is there a direct link on the web? Yes: https://play.google.com/store/apps/details?id=com.microsoft.office.word&hl=en_US

Affected Products (1)

Apps

  • Microsoft Word for Android

Security Updates (1)

Acknowledgments

<a href="https://twitter.com/fatal0_/">fatal0</a>

Revision History

  • 2020-06-09: Information published.