CVE-2019-1461

4 documents4 sources
Severity
6.5MEDIUM
EPSS
16.9%
top 5.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 10
Latest updateMay 24

Description

A denial of service vulnerability exists in Microsoft Word software when the software fails to properly handle objects in memory, aka 'Microsoft Word Denial of Service Vulnerability'.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

NVDmicrosoft/word2010, 2013, 2016+2
CVEListV5microsoft/microsoft_word7 versions+6
NVDmicrosoft/office2010, 2019+1
CVEListV5microsoft/microsoft_office4 versions+3
CVEListV5microsoft/office_365_proplus32-bit Systems, 64-bit Systems+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mjcp-9f67-vvv5: A denial of service vulnerability exists in Microsoft Word software when the software fails to properly handle objects in memory, aka 'Microsoft Word2022-05-24
CVEList
CVE-2019-1461: A denial of service vulnerability exists in Microsoft Word software when the software fails to properly handle objects in memory, aka 'Microsoft Word2019-12-10

📋Vendor Advisories

1
Microsoft
Microsoft Word Remote Code Execution Vulnerability2019-12-10
CVE-2019-1461 (MEDIUM CVSS 6.5) | A denial of service vulnerability e | cvebase.io