CVE-2019-0801
published 2019-04-09CVE-2019-0801: A remote code execution vulnerability exists when Microsoft Office fails to properly handle certain files.To exploit the vulnerability, an attacker would have…
PriorityP349high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
18.52%
96.9th percentile
A remote code execution vulnerability exists when Microsoft Office fails to properly handle certain files.To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file that points to an Excel or PowerPoint file that was also downloaded.The update addresses the vulnerability by correcting how Office handles these files., aka 'Office Remote Code Execution Vulnerability'.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office_365_proplus | — | — |
| microsoft | office_365_proplus | — | — |
| msrc | microsoft_office_2010_service_pack_2 | — | — |
| msrc | microsoft_office_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_office_2013_service_pack_1 | — | — |
| msrc | microsoft_office_2016 | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | office_365_proplus_for_32-bit_systems | — | — |
| msrc | office_365_proplus_for_64-bit_systems | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Office Remote Code Execution Vulnerability
vendor_msrc·2019-04-09·CVSS 7.8
CVE-2019-0801 [HIGH] Office Remote Code Execution Vulnerability
Office Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Microsoft Office fails to properly handle certain files.
To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file that points to an Excel or PowerPoint file that was also downloaded.
The update addresses the vulnerability by correcting how Office handles these files.
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
Microsoft Office: Microsoft Office
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely
Remediation: Click to Run
Reference: https
GHSA
GHSA-9f2h-rch5-q9wg: A remote code execution vulnerability exists when Microsoft Office fails to properly handle certain files
ghsa_unreviewed·2022-05-14
CVE-2019-0801 [HIGH] GHSA-9f2h-rch5-q9wg: A remote code execution vulnerability exists when Microsoft Office fails to properly handle certain files
A remote code execution vulnerability exists when Microsoft Office fails to properly handle certain files.To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file that points to an Excel or PowerPoint file that was also downloaded.The update addresses the vulnerability by correcting how Office handles these files., aka 'Office Remote Code Execution Vulnerability'.
No detection rules found.
No public exploits indexed.
Trendmicro
CVE-2019-0801: Microsoft Office Uri Hyperlink Hijinks
blogs_trendmicro·2019-09-24·CVSS 7.8
CVE-2019-0801 [HIGH] CVE-2019-0801: Microsoft Office Uri Hyperlink Hijinks
# CVE-2019-0801: Microsoft Office Uri Hyperlink Hijinks
Learn other Microsoft Office Uri hyperlink hijinks.
By: Simon Zuckerbraun
2019/09/24
Read time: ( words)
Save to Folio
In December of 2018, we received a report of a vulnerability in Microsoft Office from Andrea Micalizzi, also known as rgod, who is one of our frequent contributors. It was patched this April as CVE-2019-0801, and now we’d like to share the full details with you.
A somewhat obscure fact about Microsoft Office is that when installed, it registers handlers for various URI schemes. They are documented here. In general, these URI schemes can be used to launch Office applications from the browser. In particular, we’ll be interested in URIs having these formats:
ms-word:ofe|u|
ms-excel:ofe|u|
ms-powerpoint:ofe|u|
T
Trendmicro
CVE-2019-0801: Microsoft Office Uri Hyperlink Hijinks
blogs_trendmicro·2019-09-24·CVSS 7.8
CVE-2019-0801 [HIGH] CVE-2019-0801: Microsoft Office Uri Hyperlink Hijinks
## CVE-2019-0801: Microsoft Office Uri Hyperlink Hijinks
Learn other Microsoft Office Uri hyperlink hijinks.
By: Simon Zuckerbraun 2019/09/24 Read time: ( words)
Save to Folio
In December of 2018, we received a report of a vulnerability in Microsoft Office from Andrea Micalizzi, also known as rgod, who is one of our frequent contributors. It was patched this April as CVE-2019-0801 , and now we’d like to share the full details with you.
A somewhat obscure fact about Microsoft Office is that when installed, it registers handlers for various URI schemes. They are documented here . In general, these URI schemes can be used to launch Office applications from the browser. In particular, we’ll be interested in URIs having these formats:
ms-word:ofe|u|
ms-excel:ofe|u|
ms-powerpoint:ofe|u|
T
2019-04-09
Published