Remote Code Execution Vulnerability in Microsoft PowerPoint
CVE-2019-1462

7.8HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
10 December 2019

Summary

A remote code execution vulnerability exists in Microsoft PowerPoint due to improper handling of objects in memory. An attacker exploiting this vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected systems, install programs, view and modify data, and create new accounts with full user rights. The vulnerability can be triggered by convincing a user to open a specially crafted PowerPoint file, leading to serious implications for data security and system integrity. Users are advised to update their software to mitigate this risk.

Affected Version(s)

Microsoft Office 2019 for 32-bit editions

Microsoft Office 2019 for 64-bit editions

Microsoft Office 2019 for Mac

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.