CVE-2020-17019 is a remote code execution vulnerability affecting Microsoft Excel, allowing an attacker to execute arbitrary code on a victim's system. With a CVSS score of 7.8 (High), it requires user interaction (e.g., opening a malicious file) but has high impact on confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog or having public exploit code in common repositories, its EPSS score and FAUCET Risk Score indicate a notable potential for exploitation. Community discussion and media coverage suggest awareness of this vulnerability, despite no confirmed active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.