Remote Code Execution Vulnerability in Microsoft Excel Software
CVE-2019-1448
7.8HIGH
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 12 November 2019
Summary
A remote code execution vulnerability exists in Microsoft Excel when the software improperly manages objects in memory. This flaw could allow attackers to execute arbitrary code on a user's system, potentially gaining unauthorized access to sensitive data and executing actions with the privileges of the user. Users are encouraged to apply patches and updates provided by Microsoft to mitigate risks associated with this vulnerability.
Affected Version(s)
Microsoft Excel 2010 Service Pack 2 (32-bit editions)
Microsoft Excel 2010 Service Pack 2 (64-bit editions)
Microsoft Excel 2013 Service Pack 1 (32-bit editions)
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved