← All CVEs

CVE-2019-0801

high · 7.8

A remote code execution vulnerability exists when Microsoft Office fails to properly handle certain files.To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file that points to an Excel or PowerPoint file that was also downloaded.The update addresses the vulnerability by correcting how Office handles these files., aka 'Office Remote Code Execution Vulnerability'.

7.8
CVSS
18.5%
EPSS (exploit prob.)
97th
EPSS percentile
2019-04-09
Published

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-19

Affected products

VendorProductAffected versions
microsoftoffice2010
microsoftoffice2013
microsoftoffice2013
microsoftoffice2016
microsoftoffice2019
microsoftoffice_365_proplusall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-0801