cbcvebase.
CVE-2019-1297
published 2019-09-11

CVE-2019-1297: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel…

PriorityP183high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-17
Exploited in the wild
EPSS
21.80%
97.4th percentile
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftexcel
microsoftexcel
microsoftexcel
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftoffice
microsoftoffice
microsoftoffice_365_proplus
microsoftoffice_365_proplus
msrcmicrosoft_excel_2010_service_pack_2
msrcmicrosoft_excel_2013_rt_service_pack_1
msrcmicrosoft_excel_2013_service_pack_1
msrcmicrosoft_excel_2016
msrcmicrosoft_office_2016_for_mac
msrcmicrosoft_office_2019_for_32-bit_editions
msrcmicrosoft_office_2019_for_64-bit_editions

Detection & IOCsextracted from sources · hover to see the quote

  • Attack vector requires a user to open a specially crafted Microsoft Excel file; the Preview Pane is NOT an attack vector — file must be explicitly opened.
  • In email-based delivery, the attacker sends a specially crafted Excel file as an attachment and socially engineers the recipient into opening it.
  • In web-based delivery, the attacker hosts or compromises a site serving a specially crafted Excel file; no drive-by — user must click a link and then open the file.
  • The Preview Pane is explicitly confirmed as NOT an attack vector; detections should focus on file-open events, not preview events.
  • ·Microsoft assessed exploitation likelihood as 'Less Likely' for both latest and older software releases at time of disclosure, and the vulnerability was not publicly disclosed or exploited in the wild at patch time.
  • ·CISA added this to the Known Exploited Vulnerabilities catalog with a remediation due date of 2022-03-17, indicating confirmed in-the-wild exploitation occurred after initial disclosure.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.