Endpoint Vulnerability

Microsoft Office Information Disclosure Vulnerability

Description

An information disclosure vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user s system. To exploit the vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The security update addresses the vulnerability by correcting how Microsoft Office handles objects in memory.

Affected Products

Microsoft Office 2010 Service Pack 2 (32-bit editions),Microsoft Office 2010 Service Pack 2 (64-bit editions),Microsoft Office 2013 Service Pack 1 (64-bit editions),Microsoft Office 2016 x64,Microsoft Office 2013 RT Service Pack 1,Microsoft Office 2019 for 64-bit editions,Microsoft Office 2013 Service Pack 1 (32-bit editions),Office 365 ProPlus for 64-bit Systems,Microsoft Office 2019 for 32-bit editions,Office 365 ProPlus for 32-bit Systems

References

CVE-2019-1402,