#VU21650 Input validation error in Microsoft products - CVE-2019-1331
Published: October 9, 2019
Microsoft Excel
Microsoft Office
Microsoft Office for macOS
Excel Services on Microsoft SharePoint Server
Office Online Server
Microsoft SharePoint Server
Microsoft
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input when the software fails to properly handle objects in memory in Microsoft Excel software.
Successful exploitation of the vulnerability allows remote code execution but requires that a user open a specially crafted file with an affected version of Microsoft Excel.