CVE-2019-0671
published 2019-03-05CVE-2019-0671: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office…
PriorityP345high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
14.82%
96.3th percentile
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0672, CVE-2019-0673, CVE-2019-0674, CVE-2019-0675.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| msrc | microsoft_office_2010_service_pack_2 | — | — |
| msrc | microsoft_office_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_office_2013_service_pack_1 | — | — |
| msrc | microsoft_office_2016 | — | — |
| msrc | microsoft_office_2019 | — | — |
| msrc | office_365_proplus | — | — |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1703 | — | — |
| msrc | windows_10_version_1709 | — | — |
| msrc | windows_10_version_1803 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_7 | — | — |
| msrc | windows_8.1 | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2008 | — | — |
| msrc | windows_server_2008_r2 | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
vendor_msrc·2019-02-12·CVSS 7.8
CVE-2019-0671 [HIGH] Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerability by correcting the way the Microsoft Office Access Connectivity Engine handles objects in memory.
Microsoft Office: Microsoft Office
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Remediatio
GHSA
GHSA-9q4x-jggm-5gw3: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft
ghsa_unreviewed·2022-05-13·CVSS 7.8
CVE-2019-0671 [HIGH] GHSA-9q4x-jggm-5gw3: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0672, CVE-2019-0673, CVE-2019-0674, CVE-2019-0675.
GHSA
GHSA-9jx6-mvxq-rqv5: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft
ghsa_unreviewed·2022-05-13·CVSS 7.8
CVE-2019-0672 [HIGH] GHSA-9jx6-mvxq-rqv5: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0671, CVE-2019-0673, CVE-2019-0674, CVE-2019-0675.
GHSA
GHSA-hhj6-ph7m-947v: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft
ghsa_unreviewed·2022-05-13·CVSS 7.8
CVE-2019-0673 [HIGH] GHSA-hhj6-ph7m-947v: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0671, CVE-2019-0672, CVE-2019-0674, CVE-2019-0675.
GHSA
GHSA-xqfc-cx8v-9v3h: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft
ghsa_unreviewed·2022-05-13·CVSS 7.8
CVE-2019-0674 [HIGH] GHSA-xqfc-cx8v-9v3h: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0671, CVE-2019-0672, CVE-2019-0673, CVE-2019-0675.
GHSA
GHSA-3cw4-7rq6-46gx: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft
ghsa_unreviewed·2022-05-13·CVSS 7.8
CVE-2019-0675 [HIGH] GHSA-3cw4-7rq6-46gx: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0671, CVE-2019-0672, CVE-2019-0673, CVE-2019-0674.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-9810 Mozilla: IonMonkey MArraySlice has incorrect alias information
bugzilla·2019-03-24·CVSS 8.8
CVE-2019-9810 [HIGH] CVE-2019-9810 Mozilla: IonMonkey MArraySlice has incorrect alias information
CVE-2019-9810 Mozilla: IonMonkey MArraySlice has incorrect alias information
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-10/#CVE-2019-9810
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Richard Zhu and Amat Cama via Trend Micro's Zero Day Initiative
---
Statement:
In general, this flaw be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:0671 https://access.redhat.com/erra
Bugzilla
CVE-2019-9813 Mozilla: Ionmonkey type confusion with __proto__ mutations
bugzilla·2019-03-24·CVSS 8.8
CVE-2019-9813 [HIGH] CVE-2019-9813 Mozilla: Ionmonkey type confusion with __proto__ mutations
CVE-2019-9813 Mozilla: Ionmonkey type confusion with __proto__ mutations
Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-10/#CVE-2019-9813
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Niklas Baumstark via Trend Micro's Zero Day Initiative
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:0671 https://access.redhat.com/errata/RHSA-2019:0671
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2019:0672 https://access.redhat.com/errata/RHSA-2019:0672
---
This issue has been addressed
2019-03-05
Published