MEDIUM · 5.5

CVE-2019-0540

A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credent...

Vulnerability Description

A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'.

CVSS Score

5.5

MEDIUM

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
MicrosoftExcel Viewer-
MicrosoftOffice2010
MicrosoftOffice 365 Proplus-
MicrosoftPowerpoint Viewer-
MicrosoftWord Viewer-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-0540?

CVE-2019-0540 is a vulnerability with a CVSS score of 5.5 (MEDIUM). A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credent...

How severe is CVE-2019-0540?

CVE-2019-0540 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-0540?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Excel Viewer, Microsoft Office, Microsoft Office 365 Proplus, Microsoft Powerpoint Viewer, Microsoft Word Viewer.