← All CVEs

CVE-2019-0585

high · 8.8

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Microsoft SharePoint, Microsoft Office Online Server, Microsoft Word, Microsoft SharePoint Server.

8.8
CVSS
22.0%
EPSS (exploit prob.)
98th
EPSS percentile
2019-01-08
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

VendorProductAffected versions
microsoftoffice2010
microsoftoffice2016
microsoftoffice2019
microsoftoffice2019
microsoftoffice_365_proplusall versions
microsoftoffice_online_serverall versions
microsoftoffice_web_apps_server2010
microsoftoffice_word_viewerall versions
microsoftsharepoint_server2013
microsoftsharepoint_server2016
microsoftsharepoint_server2019
microsoftword2010
microsoftword2013
microsoftword2013
microsoftword2016
microsoftword_automation_servicesall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-0585