CVE-2020-1223: Microsoft Word

High severity, CVSS 8.8. EPSS: 8% chance of exploitation in the next 30 days.

A remote code execution vulnerability exists when Microsoft Word for Android fails to properly handle certain files.To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file.The update addresses the vulnerability by correcting how Microsoft Word for Android handles specially crafted URL files., aka 'Word for Android Remote Code Execution Vulnerability'.

Affected products

  • Microsoft Word: affected versions not specified

Published 2020-06-09. Last modified 2026-06-17.