106863vdb entry
http://www.securityfocus.com/bid/106863 CVE-2019-0540
MEDIUM
Record summary
CVE-2019-0540 has a selected CVSS score of 5.5 (medium).
Description
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'.
Description source: CVE List
Affected products and versions
5| Product | Source | Version range | Status |
|---|---|---|---|
Microsoft Excel ViewerBrowse Microsoft / Microsoft Excel Viewer | CVE List | Version range not supplied | affected |
Microsoft OfficeBrowse Microsoft / Microsoft Office | CVE List | 2010 Service Pack 2 (32-bit editions) | affected |
| 2010 Service Pack 2 (64-bit editions) | affected | ||
| 2013 Service Pack 1 (32-bit editions) | affected | ||
| 2013 Service Pack 1 (64-bit editions) | affected | ||
| 2013 RT Service Pack 1 | affected | ||
| 2016 (32-bit edition) | affected | ||
| 2016 (64-bit edition) | affected | ||
| 2019 for 32-bit editions | affected | ||
| 2019 for 64-bit editions | affected | ||
| Word Viewer | affected | ||
Microsoft Office Compatibility PackBrowse Microsoft / Microsoft Office Compatibility Pack | CVE List | Service Pack 3 | affected |
Microsoft PowerPoint ViewerBrowse Microsoft / Microsoft PowerPoint Viewer | CVE List | Version range not supplied | affected |
Office 365 ProPlusBrowse Microsoft / Office 365 ProPlus | CVE List | 32-bit Systems | affected |
| 64-bit Systems | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-0540 portal.msrc.microsoft.comConfirmation
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0540