Out-of-bounds read in Microsoft products - CVE-2019-1446
Published: November 12, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition when processing untrusted data. A remote attacker can create a specially crafted Excel file, trick the victim into opening it, trigger out-of-bounds read error and read contents of memory on the system.
Affected software
Microsoft Excel
Excel Services on Microsoft SharePoint Server
Microsoft Excel for macOS
Microsoft SharePoint Server
Office Online Server