CVE-2019-1442High

Microsoft Office Security Feature Bypass Vulnerability

Published
November 12, 2019
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A security feature bypass vulnerability exists when Microsoft Office does not validate URLs. An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials. An attacker who successfully exploited this vulnerability could perform a phishing attack. The update addresses the vulnerability by ensuring Microsoft Office properly validates URLs.

🎯 Affected products1

  • Microsoft SharePoint Server 2019

✅ Remediation

KB4484142 (Security Update) KB4484149 (Security Update)

🔗 References (3)