CVE-2020-1349

HIGH

Microsoft 365 Apps - Remote Code Execution

Title source: rule
STIX 2.1

Description

A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka 'Microsoft Outlook Remote Code Execution Vulnerability'.

Exploits (1)

nomisec WRITEUP 11 stars
by 0neb1n · poc
https://github.com/0neb1n/CVE-2020-1349

Scores

CVSS v3 7.8
EPSS 0.2597
EPSS Percentile 96.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

Status published
Products (5)
microsoft/365_apps
microsoft/office 2019
microsoft/outlook 2010 sp2
microsoft/outlook 2013 sp1 (2 CPE variants)
microsoft/outlook 2016
Published Jul 14, 2020
Tracked Since Feb 18, 2026