CVE-2020-1502 is an information disclosure vulnerability in Microsoft Word, affecting Microsoft 365 Apps, Office, Office Online Server, and SharePoint Server. An attacker could exploit this by crafting a malicious document that, when opened, improperly discloses memory contents. This is a medium-severity vulnerability (CVSS 5.5) requiring user interaction and knowledge of memory addresses, with a high impact on confidentiality. While it has a high FAUCET Risk Score, there is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and limited community discussion or media coverage beyond its initial disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2019:*:*:*:*:-:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:office_online_server:-:*:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.