PT-2019-1138 · Microsoft · Office 365 Proplus+1
Menahem Breuer
+1
·
Published
2019-01-08
·
Updated
2020-08-24
·
CVE-2019-0560
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Microsoft Office (affected versions not specified)
Office 365 ProPlus
Description:
An information disclosure issue exists due to Microsoft Office improperly disclosing the contents of its memory. This could allow a remote attacker to access protected information using a specially crafted file. The exploitation of this issue may enable an attacker to compromise the user's computer or data.
Recommendations:
For Office 365 ProPlus, update to a version that includes the fix for this issue.
For Microsoft Office, at the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office
Office 365 Proplus