CVE-2020-16918: Microsoft 365 Apps

High severity, CVSS 7.8. EPSS: 3.9% chance of exploitation in the next 30 days.

<p>A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.</p> <p>An attacker who successfully exploited the vulnerability would gain execution on a victim system.</p> <p>The security update addresses the vulnerability by correcting how the Base3D rendering engine handles memory.</p>

Affected products

  • Microsoft 365 Apps: affected versions not specified
  • Microsoft 3d Viewer: affected versions not specified

Published 2020-10-16. Last modified 2026-06-17.