CVE-2019-1442Origin Validation Error in Microsoft Sharepoint Server

Severity
5.5MEDIUMNVD
EPSS
7.1%
top 8.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12
Latest updateMay 24

Description

A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wf6f-rf6g-4xh8: A security feature bypass vulnerability exists when Microsoft Office does not validate URLs2022-05-24
CVEList
CVE-2019-1442: A security feature bypass vulnerability exists when Microsoft Office does not validate URLs2019-11-12

📋Vendor Advisories

1
Microsoft
Microsoft Office Security Feature Bypass Vulnerability2019-11-12
CVE-2019-1442 — Origin Validation Error in Microsoft | cvebase