CVE-2019-0540

CWE-601Open Redirect4 documents4 sources
Severity
5.5MEDIUM
EPSS
22.2%
top 4.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 5
Latest updateMay 13

Description

A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

NVDmicrosoft/office4 versions+3
CVEListV5microsoft/microsoft_office10 versions+9
CVEListV5microsoft/office_365_proplus32-bit Systems, 64-bit Systems+1
CVEListV5microsoft/microsoft_excel_viewerunspecified

Patches

🔴Vulnerability Details

2
GHSA
GHSA-64wm-87jc-34mv: A security feature bypass vulnerability exists when Microsoft Office does not validate URLs2022-05-13
CVEList
CVE-2019-0540: A security feature bypass vulnerability exists when Microsoft Office does not validate URLs2019-03-06

📋Vendor Advisories

1
Microsoft
Microsoft Office Security Feature Bypass Vulnerability2019-02-12
CVE-2019-0540 (MEDIUM CVSS 5.5) | A security feature bypass vulnerabi | cvebase.io