CVE-2019-0946High
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Microsoft Office Access Connectivity Engine handles objects in memory.
🎯 Affected products11
- Microsoft Office 2010 Service Pack 2 (32-bit editions)
- Microsoft Office 2010 Service Pack 2 (64-bit editions)
- Microsoft Office 2013 RT Service Pack 1
- Microsoft Office 2013 Service Pack 1 (32-bit editions)
- Microsoft Office 2013 Service Pack 1 (64-bit editions)
- Microsoft Office 2016 (32-bit edition)
- Microsoft Office 2016 (64-bit edition)
- Microsoft Office 2019 for 32-bit editions
- Microsoft Office 2019 for 64-bit editions
- Office 365 ProPlus for 32-bit Systems
- Office 365 ProPlus for 64-bit Systems
✅ Remediation
KBClick to Run (Security Update) KB4464551 (Security Update) KB4464567 (Security Update) KB4464561 (Security Update)
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-0946
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=13729403-a24e-46e3-84c5-f99a99a9ba98
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=97672abf-8dad-405f-82dc-67ce52430d7d
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=994ba722-0458-4ed1-8633-141258db5ab4
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=d83f23b1-ceec-4f2e-8bc0-eadfdb13e036
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=4fe2f766-7816-489d-8bdb-5fe70f41954e
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=b76ad451-05da-46d6-879a-57a5dc3d1ad3