cbcvebase.
CVE-2019-1331
published 2019-10-10

CVE-2019-1331: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel…

PriorityP357high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
ITW
Exploited in the wild
EPSS
17.88%
96.8th percentile
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1327.

Affected

44 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftexcel
microsoftexcel
microsoftexcel
microsoftexcel
microsoftexcel_services_on_microsoft_sharepoint_server_2010_service_pack_2
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_sharepoint_enterprise_server
microsoftoffice

Detection & IOCsextracted from sources · hover to see the quote

  • Attack vector requires a user to open a specially crafted Microsoft Excel file; the Preview Pane is NOT an attack vector — file must be actively opened.
  • In email-based delivery, the attacker sends a specially crafted Excel file as an attachment and socially engineers the recipient into opening it.
  • In web-based delivery, the attacker hosts or compromises a site serving a specially crafted Excel file; no drive-by — user must click a link and then open the file.
  • The Preview Pane is confirmed NOT an attack vector; detections should focus on Excel process launch/open events, not preview handlers.
  • Successful exploitation runs arbitrary code in the context of the current user via Microsoft Excel; monitor for anomalous child processes spawned by EXCEL.EXE.
  • ·Exploit status at time of advisory: not publicly disclosed and not exploited in the wild; exploitation assessed as 'Less Likely' for both latest and older software releases.
  • ·This CVE is distinct from CVE-2019-1327, which is a separate Microsoft Excel RCE; ensure detections and patch tracking do not conflate the two.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.