CVE-2019-0801High
Office Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
A remote code execution vulnerability exists when Microsoft Office fails to properly handle certain files. To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file that points to an Excel or PowerPoint file that was also downloaded. The update addresses the vulnerability by correcting how Office handles these files.
🎯 Affected products11
- Microsoft Office 2010 Service Pack 2 (32-bit editions)
- Microsoft Office 2010 Service Pack 2 (64-bit editions)
- Microsoft Office 2013 RT Service Pack 1
- Microsoft Office 2013 Service Pack 1 (32-bit editions)
- Microsoft Office 2013 Service Pack 1 (64-bit editions)
- Microsoft Office 2016 (32-bit edition)
- Microsoft Office 2016 (64-bit edition)
- Microsoft Office 2019 for 32-bit editions
- Microsoft Office 2019 for 64-bit editions
- Office 365 ProPlus for 32-bit Systems
- Office 365 ProPlus for 64-bit Systems
✅ Remediation
KBClick to Run (Security Update) KB4462242 (Security Update) KB4462223 (Security Update) KB4464504 (Security Update)
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-0801
- patchhttps://www.microsoft.com/download/details.aspx?familyid=b0a43be8-5798-4d1c-b15b-02aadefc0c22
- patchhttps://www.microsoft.com/download/details.aspx?familyid=45529b1e-40bd-4219-adfa-fea835995d10
- patchhttps://www.microsoft.com/download/details.aspx?familyid=ae3c90b4-c603-4e86-8142-b4623d3daa56
- patchhttps://www.microsoft.com/download/details.aspx?familyid=425b4af2-686f-4c21-b394-9d5470af739d
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=d84a593d-83d5-47d2-9c0b-e575562cdc10
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=b9bb977e-9bb1-4f27-8a88-e441bff6aa1f