CVE-2020-1581: Microsoft 365 Apps
High severity, CVSS 7.8. EPSS: 3.7% chance of exploitation in the next 30 days.
An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) components handle objects in memory. An attacker who successfully exploited the vulnerability could elevate privileges. The attacker would need to already have the ability to execute code on the system. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The security update addresses the vulnerability by correcting how Microsoft Office Click-to-Run (C2R) components handle objects in memory.
Affected products
- Microsoft 365 Apps: affected versions not specified
- Microsoft Office: version 2013 only; version 2019 only
Published 2020-08-17. Last modified 2026-06-17.