CVE-2019-1402 PUBLISHED CVSS 5.5 MEDIUM

An information disclosure vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Information Disclosure Vulnerability'.

EPSS 2.12% · 84.0th percentile

Risk Scores

CVSS v3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
2.12%
84.0th percentile

Affected Products

VendorProductVersions
MicrosoftOffice 365 ProPlus32-bit Systems, 64-bit Systems
microsoftoffice_365
microsoftoffice2013, 2013, 2016
MicrosoftMicrosoft Office2010 Service Pack 2 (32-bit editions), 2019 for 64-bit editions, 2010 Service Pack 2 (64-bit editions)

Timeline

References

Open in Interactive Console →