CVE-2019-0801

HIGH

Microsoft Office - Remote Code Execution via Crafted URL File Handling

Title source: llm
STIX 2.1

Description

A remote code execution vulnerability exists when Microsoft Office fails to properly handle certain files.To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file that points to an Excel or PowerPoint file that was also downloaded.The update addresses the vulnerability by correcting how Office handles these files., aka 'Office Remote Code Execution Vulnerability'.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://www.zerodayinitiative.com/advisories/ZDI-19-358/

Scores

CVSS v3 7.8
EPSS 0.1852
EPSS Percentile 97.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-19
Status published
Products (5)
microsoft/office 2010 sp2
microsoft/office 2013 sp1 (2 CPE variants)
microsoft/office 2016
microsoft/office 2019
microsoft/office_365_proplus
Published Apr 09, 2019
Tracked Since Feb 18, 2026