CVE-2020-0697 (CNNVD-202002-565)
中文标题:
Microsoft Office 365 ProPlus 安全漏洞
英文标题:
An elevation of privilege vulnerability exists in Microsoft Office OLicenseHeartbeat task, where an ...
漏洞描述
中文描述:
Microsoft Office是美国微软(Microsoft)公司的一款办公软件套件产品。该产品常用组件包括Word、Excel、Access、Powerpoint、FrontPage等。 Microsoft Office 365 ProPlus中的OLicenseHeartbeat任务存在提权漏洞。攻击者可借助特制的文件利用该漏洞以SYSTEM身份运行该任务。以下产品及版本受到影响: Office 365 ProPlus版本。
英文描述:
An elevation of privilege vulnerability exists in Microsoft Office OLicenseHeartbeat task, where an attacker who successfully exploited this vulnerability could run this task as SYSTEM.To exploit the vulnerability, an authenticated attacker would need to place a specially crafted file in a specific location, thereby allowing arbitrary file corruption.The security update addresses the vulnerability by correcting how the process validates the log file., aka 'Microsoft Office Tampering Vulnerability'.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Microsoft | Office 365 ProPlus | 32-bit Systems | - | - |
cpe:2.3:a:microsoft:office_365_proplus:32-bit_systems:*:*:*:*:*:*:*
|
| Microsoft | Office 365 ProPlus | 64-bit Systems | - | - |
cpe:2.3:a:microsoft:office_365_proplus:64-bit_systems:*:*:*:*:*:*:*
|
| microsoft | office_365_proplus | - | - | - |
cpe:2.3:a:microsoft:office_365_proplus:-:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2020-0697 |
2025-11-11 15:20:18 | 2025-11-11 07:35:55 |
| NVD | nvd_CVE-2020-0697 |
2025-11-11 14:56:55 | 2025-11-11 07:44:23 |
| CNNVD | cnnvd_CNNVD-202002-565 |
2025-11-11 15:10:22 | 2025-11-11 07:55:34 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202002-565
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
- cvss_score: 未提取 -> 7.8
- cvss_vector: NOT_EXTRACTED -> CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- cvss_version: NOT_EXTRACTED -> 3.1
- affected_products_count: 2 -> 3
- data_sources: ['cve'] -> ['cve', 'nvd']