CVE-2019-1402High

Microsoft Office Information Disclosure Vulnerability

Published
November 12, 2019
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

An information disclosure vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit the vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The security update addresses the vulnerability by correcting how Microsoft Office handles objects in memory.

🎯 Affected products11

  • Microsoft Office 2010 Service Pack 2 (32-bit editions)
  • Microsoft Office 2010 Service Pack 2 (64-bit editions)
  • Microsoft Office 2013 RT Service Pack 1
  • Microsoft Office 2013 Service Pack 1 (32-bit editions)
  • Microsoft Office 2013 Service Pack 1 (64-bit editions)
  • Microsoft Office 2016 (32-bit edition)
  • Microsoft Office 2016 (64-bit edition)
  • Microsoft Office 2019 for 32-bit editions
  • Microsoft Office 2019 for 64-bit editions
  • Office 365 ProPlus for 32-bit Systems
  • Office 365 ProPlus for 64-bit Systems

✅ Remediation

KBClick to Run (Security Update) KB4484113 (Security Update) KB4484127 (Security Update) KB4484119 (Security Update)

🔗 References (8)