CVE-2019-1331

HIGH IN THE WILD

Microsoft Excel - Remote Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2019-1331 has been observed exploited in the wild (reported by InTheWild.io).

Description

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1327.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.1788
EPSS Percentile 96.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

InTheWild.io 2020-07-15
Status published
Products (10)
microsoft/excel 2010 sp2
microsoft/excel 2013 sp1 (2 CPE variants)
microsoft/excel 2016
microsoft/excel_services
microsoft/office 2010 sp2
microsoft/office 2013 sp1 (2 CPE variants)
microsoft/office 2016 (2 CPE variants)
microsoft/office 2019 (2 CPE variants)
microsoft/office_365_proplus
microsoft/office_online_server
Published Oct 10, 2019
Tracked Since Feb 18, 2026