Input validation error in Microsoft products - CVE-2019-0540
Published: February 13, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a phishing attack.
The vulnerability exists due to insufficient validation of URLs when processing Microsoft Office files. A remote attacker can create a specially crafted file, trick the victim into opening it and entering credentials.
Successful exploitation of the vulnerability may allow an attacker to perform a phishing attack and gain access to sensitive information.
Affected software
Microsoft Excel
Microsoft PowerPoint
Microsoft Office Compatibility Pack
Microsoft Office