Input validation error in Microsoft products - CVE-2019-1331

 

Input validation error in Microsoft products - CVE-2019-1331

Published: October 9, 2019


Vulnerability identifier: #VU21650
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1331
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insufficient validation of user-supplied input when the software fails to properly handle objects in memory in Microsoft Excel software.

Successful exploitation of the vulnerability allows remote code execution but requires that a user open a specially crafted file with an affected version of Microsoft Excel.


Affected software

Microsoft Office
Microsoft Excel
Excel Services on Microsoft SharePoint Server
Microsoft Office for macOS
Microsoft SharePoint Server
Office Online Server

How to mitigate CVE-2019-1331

Install update from vendor's website.


External References

Related Security Bulletins