CVE-2019-0827High
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Microsoft Office Access Connectivity Engine handles objects in memory.
🎯 Affected products11
- Microsoft Office 2010 Service Pack 2 (32-bit editions)
- Microsoft Office 2010 Service Pack 2 (64-bit editions)
- Microsoft Office 2013 RT Service Pack 1
- Microsoft Office 2013 Service Pack 1 (32-bit editions)
- Microsoft Office 2013 Service Pack 1 (64-bit editions)
- Microsoft Office 2016 (32-bit edition)
- Microsoft Office 2016 (64-bit edition)
- Microsoft Office 2019 for 32-bit editions
- Microsoft Office 2019 for 64-bit editions
- Office 365 ProPlus for 32-bit Systems
- Office 365 ProPlus for 64-bit Systems
✅ Remediation
KBClick to Run (Security Update) KB4462213 (Security Update) KB4464520 (Security Update) KB4462204 (Security Update)
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-0827
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=1d5c6221-e4d8-4cf3-9d91-7fe8da0f0994
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=19352c25-ea16-40d3-b015-c5e7e0a1cff4
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=c50d78a0-bc94-48a4-91bd-c4d5916c1708
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=34e44967-eb70-45a2-8695-bd63c0f60362
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=fb5ed147-d01f-40f0-8dad-689d45d3a1c5
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=ebf52bde-972d-4a49-aad5-250eaa52d656