CVE-2019-1109
Published Jul 15, 2019
Last updated 5 years ago
Overview
- Description
- A spoofing vulnerability exists when Microsoft Office Javascript does not check the validity of the web page making a request to Office documents.An attacker who successfully exploited this vulnerability could read or write information in Office documents.The security update addresses the vulnerability by correcting the way that Microsoft Office Javascript verifies trusted web pages., aka 'Microsoft Office Spoofing Vulnerability'.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 9.1
- Impact score
- 5.2
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 6.4
- Impact score
- 4.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-20
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "120690A6-E0A1-4E36-A35A-C87109ECC064" }, { "criteria": "cpe:2.3:a:microsoft:office:2013:sp1:*:*:rt:*:*:*", "vulnerable": true, "matchCriteriaId": "F7DDFFB8-2337-4DD7-8120-56CC8EF134B4" }, { "criteria": "cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E0B3B0BC-C7C6-4687-AD72-DCA29FF9AE3A" }, { "criteria": "cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FF177984-A906-43FA-BF60-298133FBBD6B" }, { "criteria": "cpe:2.3:a:microsoft:office_365:-:*:*:*:proplus:*:*:*", "vulnerable": true, "matchCriteriaId": "42B167E5-746F-457D-821D-42EF3E3CD8B7" } ], "operator": "OR" } ] } ]