CVE-2019-1109
published 2019-07-15CVE-2019-1109: A spoofing vulnerability exists when Microsoft Office Javascript does not check the validity of the web page making a request to Office documents.An attacker…
PriorityP351critical9.1CVSS 3.0
AVNACLPRNUINSUCHIHAN
EPSS
4.24%
89.9th percentile
A spoofing vulnerability exists when Microsoft Office Javascript does not check the validity of the web page making a request to Office documents.An attacker who successfully exploited this vulnerability could read or write information in Office documents.The security update addresses the vulnerability by correcting the way that Microsoft Office Javascript verifies trusted web pages., aka 'Microsoft Office Spoofing Vulnerability'.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office_365_proplus | — | — |
| microsoft | office_365_proplus | — | — |
| msrc | microsoft_office_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_office_2013_service_pack_1 | — | — |
| msrc | microsoft_office_2016 | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | office_365_proplus_for_32-bit_systems | — | — |
| msrc | office_365_proplus_for_64-bit_systems | — | — |
CVSS provenance
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_msrc9.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Office Spoofing Vulnerability
vendor_msrc·2019-07-09·CVSS 9.1
CVE-2019-1109 [CRITICAL] Microsoft Office Spoofing Vulnerability
Microsoft Office Spoofing Vulnerability
Description: A spoofing vulnerability exists when Microsoft Office Javascript does not check the validity of the web page making a request to Office documents.
An attacker who successfully exploited this vulnerability could read or write information in Office documents.
The security update addresses the vulnerability by correcting the way that Microsoft Office Javascript verifies trusted web pages.
FAQ: Is the Preview Pane an attack vector for this vulnerability?
Maybe. If a user has installed an Office Add-in, and then opens an email that uses the add-in in the Preview Pane, ads embedded in the add-in can cause the Preview Pane to become an attack vector.
Microsoft Office: Microsoft Office
Microsoft: Microsoft
Impact: Spoofing
Exploit Status:
GHSA
GHSA-j5h9-qc5w-q39g: A spoofing vulnerability exists when Microsoft Office Javascript does not check the validity of the web page making a request to Office documents
ghsa_unreviewed·2022-05-24
CVE-2019-1109 [CRITICAL] CWE-20 GHSA-j5h9-qc5w-q39g: A spoofing vulnerability exists when Microsoft Office Javascript does not check the validity of the web page making a request to Office documents
A spoofing vulnerability exists when Microsoft Office Javascript does not check the validity of the web page making a request to Office documents.An attacker who successfully exploited this vulnerability could read or write information in Office documents.The security update addresses the vulnerability by correcting the way that Microsoft Office Javascript verifies trusted web pages., aka 'Microsoft Office Spoofing Vulnerability'.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-07-15
Published