#VU17641 Input validation error in Microsoft products - CVE-2019-0540
Published: February 13, 2019
Microsoft Office
Microsoft Word
Microsoft Excel
Microsoft Office Compatibility Pack
Microsoft PowerPoint
Microsoft
Description
The vulnerability allows a remote attacker to perform a phishing attack.
The vulnerability exists due to insufficient validation of URLs when processing Microsoft Office files. A remote attacker can create a specially crafted file, trick the victim into opening it and entering credentials.
Successful exploitation of the vulnerability may allow an attacker to perform a phishing attack and gain access to sensitive information.