CVE-2020-1442: Microsoft Office Online Server

Medium severity, CVSS 6.1. EPSS: 1.7% chance of exploitation in the next 30 days.

A spoofing vulnerability exists when an Office Web Apps server does not properly sanitize a specially crafted request, aka 'Office Web Apps XSS Vulnerability'.

Affected products

  • Microsoft Office Online Server: affected versions not specified
  • Microsoft Office Web Apps: version 2013 only

Published 2020-07-14. Last modified 2026-06-17.