CVE-2019-0561

MEDIUM

Microsoft Word - Information Disclosure via Macro Button Handling

Title source: llm
STIX 2.1

Description

An information disclosure vulnerability exists when Microsoft Word macro buttons are used improperly, aka "Microsoft Word Information Disclosure Vulnerability." This affects Microsoft Word, Office 365 ProPlus, Microsoft Office, Word.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106399

Scores

CVSS v3 5.5
EPSS 0.0793
EPSS Percentile 94.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

Status published
Products (10)
microsoft/office 2010 sp2
microsoft/office 2016
microsoft/office 2019 (2 CPE variants)
microsoft/office_365_proplus
microsoft/office_web_apps_server 2010 sp2
microsoft/sharepoint_server 2010 sp2
microsoft/word 2010 sp2
microsoft/word 2013 sp1 (2 CPE variants)
microsoft/word 2016
microsoft/word_automation_services
Published Jan 08, 2019
Tracked Since Feb 18, 2026