← Back

CVE-2019-0540

nvd nist
Published: Mar 5, 2019Modified: Jun 17, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'.

Affected (9)

5 products
Excel Viewer
Office
Office 365 Proplus
Powerpoint Viewer
Word Viewer
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Microsoft
Version 2010 sp2
Version 2013
Version 2013 sp1
Version 2016
Version 2019
All versions
All versions
All versions

References (4)

Source: secure@microsoft.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.