Rapid7 Vulnerability & Exploit Database

Microsoft CVE-2019-0801: Office Remote Code Execution Vulnerability

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

Microsoft CVE-2019-0801: Office Remote Code Execution Vulnerability

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
04/09/2019
Created
04/22/2019
Added
04/09/2019
Modified
08/06/2019

Description

A remote code execution vulnerability exists when Microsoft Office fails to properly handle certain files. To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file that points to an Excel or PowerPoint file that was also downloaded. The update addresses the vulnerability by correcting how Office handles these files.

Solution(s)

  • msft-kb4462223-334be4e6-18ce-4d4c-a133-3c720d8c1262
  • msft-kb4462223-3abacd14-35b1-4683-bc82-2c8c60042dd5
  • msft-kb4464504-12ced240-8694-48f6-9c0a-ea5ad6c631a4
  • msft-kb4464504-c4898280-d922-4196-9d95-89d17b01ee7c

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;