7.8
CVSSv3

CVE-2019-1457

Published: 12/11/2019 Updated: 24/08/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A security feature bypass vulnerability exists in Microsoft Office software by not enforcing macro settings on an Excel document, aka 'Microsoft Office Excel Security Feature Bypass'.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft office 2016

microsoft office 2019

Recent Articles

Microsoft Patch Tuesday – November 2019
Symantec Threat Intelligence Blog • Ratheesh PM • 15 Nov 2024

This month the vendor has patched 75 vulnerabilities, 14 of which are rated Critical.

Posted: 15 Nov, 201922 Min ReadThreat Intelligence SubscribeMicrosoft Patch Tuesday – November 2019This month the vendor has patched 75 vulnerabilities, 14 of which are rated Critical.As always, customers are advised to follow these security best practices: Install vendor patches as soon as they are available. Run all software with the least privileges required while still maintaining functionality. Avoid handling files from unknown or questiona...

Pay ransomware crooks, or restore the network? Guess which way this city chose after weighing up the costs
The Register • Shaun Nichols in San Francisco • 10 Aug 2020

Plus: Sec wizard shows another way to pwn Mac users

In brief A city in Colorado, USA, has swallowed its pride and paid off a malware gang after deciding the cost of a network nuke-and-pave was too high. The city of Lafayette – technically a home-rule municipality – with a population of around 30,000, said it has opted to pay ransomware criminals a $45,000 (£35,000) fee after deciding that it was a better use of cash than spending time and money wiping and reformatting all of their machines. "Ransom payment was not the direction the city want...

This November, give thanks for only having one exploited Microsoft flaw for Patch Tues. And four Hyper-V escapes
The Register • Shaun Nichols in San Francisco • 12 Nov 2019

Intel joins the fun with monthly releases from Adobe, SAP

Patch Tuesday The November edition of Patch Tuesday has landed with scheduled updates from Microsoft, Adobe, and SAP, along with the debut of a new update calendar from Intel. Microsoft's monthly batch of fixes addresses 74 CVE-listed security vulnerabilities, more than a dozen of them considered to be critical risks. One of those vulnerabilities, CVE-2019-1429, is already under attack in the wild. The flaw is a remote code execution vulnerability, specifically a memory-corrupting hole, in Inter...