CVE-2020-1449: Microsoft 365 Apps

High severity, CVSS 7.8. EPSS: 4.6% chance of exploitation in the next 30 days.

A remote code execution vulnerability exists in Microsoft Project software when the software fails to check the source markup of a file, aka 'Microsoft Project Remote Code Execution Vulnerability'.

Affected products

  • Microsoft 365 Apps: affected versions not specified
  • Microsoft Office: version 2010 only; version 2013 only; version 2019 only
  • Microsoft Project 2016: affected versions not specified

Published 2020-07-14. Last modified 2026-06-17.