CVE-2019-1201
published 2019-08-14CVE-2019-1201: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully…
PriorityP342high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
4.86%
91.1th percentile
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. The file could then take actions on behalf of the logged-on user with the same permissions as the current user.
To exploit the vulnerability, a user must open a specially crafted file with an affected version of Microsoft Word software.
Two possible email attack scenarios exist for this vulnerability:
• With the first email attack scenario, an attacker could send a specially crafted email message to the user and wait for the user to click on the message. When the message renders via Microsoft Word in the Outlook Preview Pane, an attack could be triggered.
• With the second scenario, an attacker could attach a specially crafted file to an email, send it to a user, and convince them to open it.
In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file that is designed to exploit the vulnerability. However, an attacker would have no way to force the user to visit the website. Instead, an attacker would have to convince the user to click a link, typically by way of an enticement in an email or other message, and then convince the user to open the specially crafted file.
The security update addresses the vulnerability by correcting how Microsoft Word handles files in memory.
For users who view their emails in Outlook, the Preview Pane attack vector can be mitigated by disabling this feature. The following registry keys can be set to disable the Preview Pane in Outlook on Windows, either via manual editing of the registry or by modifying Group Policy.
Note Using Registry Editor incorrectly can cause serious problems that may require you to reinstall your operating system. M
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_office_2010_service_pack_2 | >= 13.0.0.0 < publication | publication |
| microsoft | microsoft_office_2016_for_mac | >= 16.0.0 < publication | publication |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2019_for_mac | >= 16.0.0 < publication | publication |
| microsoft | microsoft_office_online_server | >= 16.0.1 < publication | publication |
| microsoft | microsoft_office_web_apps_2010_service_pack_2 | >= 13.0.0 < publication | publication |
| microsoft | microsoft_office_web_apps_server_2013_service_pack_1 | >= 15.0.1 < publication | publication |
| microsoft | microsoft_sharepoint_enterprise_server_2013_service_pack_1 | >= 15.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_server_2010_service_pack_2 | >= 13.0.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < publication | publication |
| microsoft | microsoft_word_2010_service_pack_2 | >= 13.0.0.0 < publication | publication |
| microsoft | microsoft_word_2013_service_pack_1 | >= 15.0.1 < publication | publication |
| microsoft | microsoft_word_2016 | >= 16.0.1 < publication | publication |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office_365_proplus | >= 16.0.0 < publication | publication |
| microsoft | office_web_apps | — | — |
| microsoft | office_web_apps_server | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | word | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8CRITICAL
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Word Remote Code Execution Vulnerability
vendor_msrc·2019-08-13·CVSS 7.8
CVE-2019-1201 [HIGH] Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. The file could then take actions on behalf of the logged-on user with the same permissions as the current user.
To exploit the vulnerability, a user must open a specially crafted file with an affected version of Microsoft Word software.
Two possible email attack scenarios exist for this vulnerability:
• With the first email attack scenario, an attacker could send a specially crafted email message to the user and wait for the user to click on the messa
Red Hat
jenkins-plugin-blueocean: Blue Ocean did not require CSRF tokens (SECURITY-1201)
vendor_redhat·2019-01-28·CVSS 6.5
CVE-2019-1003012 [MEDIUM] CWE-352 jenkins-plugin-blueocean: Blue Ocean did not require CSRF tokens (SECURITY-1201)
jenkins-plugin-blueocean: Blue Ocean did not require CSRF tokens (SECURITY-1201)
A data modification vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-core-js/src/js/bundleStartup.js, blueocean-core-js/src/js/fetch.ts, blueocean-core-js/src/js/i18n/i18n.js, blueocean-core-js/src/js/urlconfig.js, blueocean-rest/src/main/java/io/jenkins/blueocean/rest/APICrumbExclusion.java, blueocean-web/src/main/java/io/jenkins/blueocean/BlueOceanUI.java, blueocean-web/src/main/resources/io/jenkins/blueocean/BlueOceanUI/index.jelly that allows attackers to bypass all cross-site request forgery protection in Blue Ocean API.
Package: jenkins-plugin-blueocean (Red Hat OpenShift Container Platform 3.10) - Will not fix
Package: jenkins-plugin-blueocean (Red Hat OpenShift Cont
GHSA
GHSA-3jff-2rmh-jjj7: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2019-1205 [HIGH] GHSA-3jff-2rmh-jjj7: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1201.
GHSA
GHSA-mhjc-pqhq-cf8c: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote
ghsa_unreviewed·2022-05-24·CVSS 9.8
CVE-2019-1201 [CRITICAL] GHSA-mhjc-pqhq-cf8c: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1205.
No detection rules found.
No public exploits indexed.
Checkpoint
19th August – Threat Intelligence Bulletin
blogs_checkpoint·2019-08-19
CVE-2019-1139 19th August – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 19th August – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 19th August 2019, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Researchers have discovered an online unsecured 23-GB ElasticSearch archive containing fingerprints, facial recognition information and unencrypted usernames and passwords of one million people. The database belongs to Suprema Security Company responsible for biometric locking systems used by the UK police, defense c
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
# August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro
Aug 14, 2019
Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the time of release, a few of the bu
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Exploits & Vulnerabilities
## August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro Aug 14, 2019 Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the time
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Exploits & Vulnerabilities
# August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro
2019/08/14
Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the time o
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Ausnutzung von Schwachstellen
## August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro Aug 14, 2019 Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the t
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Exploits y vulnerabilidades
## August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro Aug 14, 2019 Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the tim
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
## August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro Aug 14, 2019 Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the time of release, a few of the bu
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Exploits & Vulnerabilities
## August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro 2019/08/14 Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the time o
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Sfruttamento vulnerabilità
## August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro Aug 14, 2019 Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the time
Talos
Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
blogs_talos·2019-08-13·CVSS 9.1
[CRITICAL] Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
Microsoft released its monthly security update today, disclosing a variety of vulnerabilities in several of its products. The latest Patch Tuesday covers 97 vulnerabilities, 31 of which are rated “critical," 65 that are considered "important" and one "moderate."
This month’s security update covers security issues in a variety of Microsoft services and software, including certain graphics components, Outlook and the Chakra Scripting Engine. For more on our coverage of these bugs, check out our Snort advisories here, covering all of the new rules we have for this release.
### Critical vulnerabilities Microsoft disclosed 31 critical vulnerabilities this month, three of which we will highlight below.
CVE-2019-1181 and CVE-2019-1182 are both remote code execution vulnerabilities in Remote De
Tenable
Tenable Roundup for Microsoft’s August 2019 Patch Tuesday: DejaBlue
blogs_tenable·2019-08-13
Tenable Roundup for Microsoft’s August 2019 Patch Tuesday: DejaBlue
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
blogs_talos·2019-08-13·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
## Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
Microsoft released its monthly security update today, disclosing a variety of vulnerabilities in several of its products. The latest Patch Tuesday covers 97 vulnerabilities, 31 of which are rated “critical," 65 that are considered "important" and one "moderate."
This month’s security update covers security issues in a variety of Microsoft services and software, including certain graphics components, Outlook and the Chakra Scripting Engine. For more on our coverage of these bugs, check out our Snort advisories here , covering all of the new rules we have for this release.
## Critical vulnerabilities Microsoft disclosed 31 critical vulnerabilities this month, three of which we will highlight below.
CVE-2
Bugzilla
CVE-2019-1003012 jenkins-plugin-blueocean: Blue Ocean did not require CSRF tokens (SECURITY-1201)
bugzilla·2019-01-29·CVSS 6.5
CVE-2019-1003012 [MEDIUM] CVE-2019-1003012 jenkins-plugin-blueocean: Blue Ocean did not require CSRF tokens (SECURITY-1201)
CVE-2019-1003012 jenkins-plugin-blueocean: Blue Ocean did not require CSRF tokens (SECURITY-1201)
Jenkins Blue Ocean plugin before version 1.10.2 did not require CSRF tokens ("crumbs") for POST requests with the Content-Type: application/json.
Blue Ocean now requires that valid CSRF tokens are present in POST requests.
External Reference:
https://jenkins.io/security/advisory/2019-01-28/#SECURITY-1201
Upstream patches:
https://github.com/jenkinsci/blueocean-plugin/commit/1a03020b5a50c1e3f47d4b0902ec7fc78d3c86ce
Discussion:
openshift-enterprise 3.4-3.11 inclusive: affected
Once openshift3/jenkins-1-rhel7, openshift3/jenkins-2-rhel7, openshift3/jenkins-slave-base-rhel7 container images have been released with these fixes, users of all versions of openshift-enterprise-3.2+ are encour
2019-08-14
Published