SB2019100903 - Remote code execution in Microsoft Excel
Published: October 9, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2019-1327)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input when the software fails to properly handle objects in memory in Microsoft Excel software.
Successful exploitation of the vulnerability allows remote code execution but requires that a user open a specially crafted file with an affected version of Microsoft Excel.
2) Input validation error (CVE-ID: CVE-2019-1331)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input when the software fails to properly handle objects in memory in Microsoft Excel software.
Successful exploitation of the vulnerability allows remote code execution but requires that a user open a specially crafted file with an affected version of Microsoft Excel.
Remediation
Install update from vendor's website.