Msrc Microsoft Office 2019 vulnerabilities

46 known vulnerabilities affecting msrc/microsoft_office_2019.

Total CVEs
46
CISA KEV
1
actively exploited
Public exploits
5
Exploited in wild
3
Severity breakdown
CRITICAL2HIGH38MEDIUM6

Vulnerabilities

Page 3 of 3
CVE-2019-0582HIGHCVSS 7.82019-01-08
CVE-2019-0582 [HIGH] Jet Database Engine Remote Code Execution Vulnerability Jet Database Engine Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the v
msrc
CVE-2019-0585HIGHCVSS 8.82019-01-08
CVE-2019-0585 [HIGH] Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with
msrc
CVE-2019-0541MEDIUMCVSS 6.4KEVPoC2019-01-08
CVE-2019-0541 [HIGH] MSHTML Engine Remote Code Execution Vulnerability MSHTML Engine Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker coul
msrc
CVE-2018-8628HIGHCVSS 7.82018-12-11
CVE-2018-8628 [HIGH] Microsoft PowerPoint Remote Code Execution Vulnerability Microsoft PowerPoint Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take cont
msrc
CVE-2018-8577HIGHCVSS 7.82018-11-13
CVE-2018-8577 [HIGH] Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affe
msrc
CVE-2018-8432MEDIUMCVSS 5.02018-10-09
CVE-2018-8432 [HIGH] Microsoft Graphics Components Remote Code Execution Vulnerability Microsoft Graphics Components Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have to open a specially crafted file. The security update addresse
msrc