Lucene search

K
cveMicrosoftCVE-2019-0585
HistoryJan 08, 2019 - 9:29 p.m.

CVE-2019-0585

2019-01-0821:29:02
microsoft
web.nvd.nist.gov
1075
cve-2019-0585
microsoft
word
software
remote code execution
vulnerability
memory
microsoft office
viewer
office 365 proplus
sharepoint server
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0.299

Percentile

97.0%

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka “Microsoft Word Remote Code Execution Vulnerability.” This affects Word, Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Microsoft SharePoint, Microsoft Office Online Server, Microsoft Word, Microsoft SharePoint Server.

Affected configurations

Nvd
Vulners
Node
microsoftofficeMatch2010sp2
OR
microsoftofficeMatch2016mac_os_x
OR
microsoftofficeMatch2019
OR
microsoftofficeMatch2019macos
OR
microsoftoffice_365_proplusMatch-
OR
microsoftoffice_online_serverMatch-
OR
microsoftoffice_web_apps_serverMatch2010sp2
OR
microsoftoffice_word_viewerMatch-
OR
microsoftsharepoint_serverMatch2013sp1enterprise
OR
microsoftsharepoint_serverMatch2016enterprise
OR
microsoftsharepoint_serverMatch2019
OR
microsoftwordMatch2010sp2
OR
microsoftwordMatch2013sp1
OR
microsoftwordMatch2013sp1rt
OR
microsoftwordMatch2016
OR
microsoftword_automation_servicesMatch-
VendorProductVersionCPE
microsoftoffice2010cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*
microsoftoffice2016cpe:2.3:a:microsoft:office:2016:*:*:*:*:mac_os_x:*:*
microsoftoffice2019cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:*
microsoftoffice2019cpe:2.3:a:microsoft:office:2019:*:*:*:*:macos:*:*
microsoftoffice_365_proplus-cpe:2.3:a:microsoft:office_365_proplus:-:*:*:*:*:*:*:*
microsoftoffice_online_server-cpe:2.3:a:microsoft:office_online_server:-:*:*:*:*:*:*:*
microsoftoffice_web_apps_server2010cpe:2.3:a:microsoft:office_web_apps_server:2010:sp2:*:*:*:*:*:*
microsoftoffice_word_viewer-cpe:2.3:a:microsoft:office_word_viewer:-:*:*:*:*:*:*:*
microsoftsharepoint_server2013cpe:2.3:a:microsoft:sharepoint_server:2013:sp1:*:*:enterprise:*:*:*
microsoftsharepoint_server2016cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
Rows per page:
1-10 of 161

CNA Affected

[
  {
    "product": "Word",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "Automation Services on Microsoft SharePoint Server 2010 Service Pack 2"
      }
    ]
  },
  {
    "product": "Microsoft Office",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "2010 Service Pack 2 (32-bit editions)"
      },
      {
        "status": "affected",
        "version": "2010 Service Pack 2 (64-bit editions)"
      },
      {
        "status": "affected",
        "version": "2016 for Mac"
      },
      {
        "status": "affected",
        "version": "2019 for 32-bit editions"
      },
      {
        "status": "affected",
        "version": "2019 for 64-bit editions"
      },
      {
        "status": "affected",
        "version": "2019 for Mac"
      },
      {
        "status": "affected",
        "version": "Web Apps Server 2010 Service Pack 2"
      }
    ]
  },
  {
    "product": "Microsoft Office Word Viewer",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "Microsoft Office Word Viewer"
      }
    ]
  },
  {
    "product": "Microsoft SharePoint",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "Enterprise Server 2013 Service Pack 1"
      },
      {
        "status": "affected",
        "version": "Enterprise Server 2016"
      }
    ]
  },
  {
    "product": "Office",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "365 ProPlus for 32-bit Systems"
      },
      {
        "status": "affected",
        "version": "365 ProPlus for 64-bit Systems"
      }
    ]
  },
  {
    "product": "Microsoft Office Online Server",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "Microsoft Office Online Server"
      }
    ]
  },
  {
    "product": "Microsoft Word",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "2010 Service Pack 2 (32-bit editions)"
      },
      {
        "status": "affected",
        "version": "2010 Service Pack 2 (64-bit editions)"
      },
      {
        "status": "affected",
        "version": "2013 RT Service Pack 1"
      },
      {
        "status": "affected",
        "version": "2013 Service Pack 1 (32-bit editions)"
      },
      {
        "status": "affected",
        "version": "2013 Service Pack 1 (64-bit editions)"
      },
      {
        "status": "affected",
        "version": "2016 (32-bit edition)"
      },
      {
        "status": "affected",
        "version": "2016 (64-bit edition)"
      }
    ]
  },
  {
    "product": "Microsoft SharePoint Server",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "2019"
      }
    ]
  }
]

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0.299

Percentile

97.0%