Permissions, Privileges, and Access Controls in Microsoft Office for macOS and Microsoft Office - CVE-2019-1457

 

Permissions, Privileges, and Access Controls in Microsoft Office for macOS and Microsoft Office - CVE-2019-1457

Published: November 12, 2019


Vulnerability identifier: #VU22685
CSH Severity: Medium
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1457
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to Microsoft Office for Mac does not enforce macro settings on an Excel document. A remote attacker can trick the victim into opening a specially crafted Excel file and gain access to sensitive information or manipulate data.

Note, this vulnerability does not allow remote code execution.


Affected software

Microsoft Office for macOS
Microsoft Office

How to mitigate CVE-2019-1457

Install updates from vendor's website.


External References

Related Security Bulletins