Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-0801


A remote code execution vulnerability exists when Microsoft Office fails to properly handle certain files.To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file that points to an Excel or PowerPoint file that was also downloaded.The update addresses the vulnerability by correcting how Office handles these files., aka 'Office Remote Code Execution Vulnerability'.


Published

2019-04-09T21:29:00.957

Last Modified

2024-11-21T04:17:18.350

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.8 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-19

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application microsoft office 2010 Yes
Application microsoft office 2013 Yes
Application microsoft office 2013 Yes
Application microsoft office 2016 Yes
Application microsoft office 2019 Yes
Application microsoft office_365_proplus * Yes

References