CVE-2020-16957: Microsoft 365 Apps
High severity, CVSS 7.8. EPSS: 3.9% chance of exploitation in the next 30 days.
<p>A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.</p> <p>An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.</p> <p>The update addresses the vulnerability by correcting the way the Microsoft Office Access Connectivity Engine handles objects in memory.</p>
Affected products
Published 2020-10-16. Last modified 2026-06-17.