CVE-2019-0801
HIGHMicrosoft Office - Remote Code Execution via Crafted URL File Handling
Title source: llmDescription
A remote code execution vulnerability exists when Microsoft Office fails to properly handle certain files.To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file that points to an Excel or PowerPoint file that was also downloaded.The update addresses the vulnerability by correcting how Office handles these files., aka 'Office Remote Code Execution Vulnerability'.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://www.zerodayinitiative.com/advisories/ZDI-19-358/
Patch, Vendor Advisory x_refsource_misc
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0801
Scores
CVSS v3
7.8
EPSS
0.1852
EPSS Percentile
97.0%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-19
Status
published
Products (5)
microsoft/office
2010 sp2
microsoft/office
2013 sp1 (2 CPE variants)
microsoft/office
2016
microsoft/office
2019
microsoft/office_365_proplus
Published
Apr 09, 2019
Tracked Since
Feb 18, 2026