CVE-2019-1402Sensitive Information Exposure in Microsoft Office

Severity
5.5MEDIUMNVD
EPSS
2.1%
top 15.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12
Latest updateMay 24

Description

An information disclosure vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Information Disclosure Vulnerability'.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

NVDmicrosoft/office4 versions+3
CVEListV5microsoft/microsoft_office9 versions+8
CVEListV5microsoft/office_365_proplus32-bit Systems, 64-bit Systems+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-59hc-rfcg-f7w2: An information disclosure vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microso2022-05-24
CVEList
CVE-2019-1402: An information disclosure vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microso2019-11-12

📋Vendor Advisories

1
Microsoft
Microsoft Office Information Disclosure Vulnerability2019-11-12
CVE-2019-1402 — Sensitive Information Exposure | cvebase