CVE-2019-0540
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.8%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 12.78% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- microsoft/excel viewer · microsoft/office · microsoft/office 365 proplus · microsoft/powerpoint viewer · microsoft/word viewer
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/106863Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0540Patch, Vendor Advisory
- http://www.securityfocus.com/bid/106863Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0540Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.