High severity7.8NVD Advisory· Published Jul 14, 2020· Updated Jun 17, 2026
CVE-2020-1449
CVE-2020-1449
Description
A remote code execution vulnerability exists in Microsoft Project software when the software fails to check the source markup of a file, aka 'Microsoft Project Remote Code Execution Vulnerability'.
Affected products
14cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:x64:*+ 4 more
- cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:x64:*
- cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:x86:*
- cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:x64:*
- cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:x86:*
- cpe:2.3:a:microsoft:office:2019:*:*:*:*:-:*:*
cpe:2.3:a:microsoft:project_2016:-:*:*:*:*:*:x64:*+ 1 more
- cpe:2.3:a:microsoft:project_2016:-:*:*:*:*:*:x64:*
- cpe:2.3:a:microsoft:project_2016:-:*:*:*:*:*:x86:*
- Microsoft/Microsoft 365 Apps for Enterprise for 32-bit Systemsv5Range: unspecified
- Microsoft/Microsoft 365 Apps for Enterprise for 64-bit Systemsv5Range: unspecified
- Range: 2019 for 32-bit editions
Patches
Vulnerability mechanics
References
1- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1449nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.