← Back

CVE-2019-1109

nvd nist
Published: Jul 15, 2019Modified: Jun 17, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

A spoofing vulnerability exists when Microsoft Office Javascript does not check the validity of the web page making a request to Office documents.An attacker who successfully exploited this vulnerability could read or write information in Office documents.The security update addresses the vulnerability by correcting the way that Microsoft Office Javascript verifies trusted web pages., aka 'Microsoft Office Spoofing Vulnerability'.

Affected (5)

2 products
Office
Office 365
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 2013 sp1
Version 2013 sp1
Version 2016
Version 2019
All versions

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.