Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2019-1457

Опубликовано: 12 нояб. 2019
Источник: msrc
EPSS Низкий

Описание

Microsoft Office Excel Security Feature Bypass

A security feature bypass vulnerability exists in Microsoft Office software by not enforcing macro settings on an Excel document. The security feature bypass by itself does not allow arbitrary code execution. To successfully exploit the vulnerability, an attacker would have to embed a control in an Excel worksheet that specifies a macro should be run.   To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted file with an affected version of Microsoft Office software.   The security update addresses the vulnerability by enforcing macro settings on Excel documents.

FAQ

Is the Preview Pane an attack vector for this vulnerability?

No, the Preview Pane is not an attack vector.

Обновления

ПродуктСтатьяОбновление
Microsoft Office 2016 for Mac
Microsoft Office 2019 for Mac

Показывать по

Возможность эксплуатации

Publicly Disclosed

Yes

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

EPSS

Процентиль: 90%
0.05719
Низкий

Связанные уязвимости

CVSS3: 7.8
nvd
почти 6 лет назад

A security feature bypass vulnerability exists in Microsoft Office software by not enforcing macro settings on an Excel document, aka 'Microsoft Office Excel Security Feature Bypass'.

github
больше 3 лет назад

A security feature bypass vulnerability exists in Microsoft Office software by not enforcing macro settings on an Excel document, aka 'Microsoft Office Excel Security Feature Bypass'.

CVSS3: 7.8
fstec
почти 6 лет назад

Уязвимость пакета программ Microsoft Office, связанная с недостаточной проверкой данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 90%
0.05719
Низкий