Kaspersky ID:
KLA11396
Detekováno:
01/08/2019
Aktualizováno:
01/28/2026

Popis

Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to obtain sensitive information, execute arbitrary code, gain privileges, spoof user interface.

Below is a complete list of vulnerabilities:

  1. An information disclosure vulnerability in Microsoft Office can be exploited remotely via specially designed document file to obtain sensitive information;
  2. An information disclosure vulnerability in Microsoft Outlook can be exploited remotely via specially crafted email to obtain sensitive information;
  3. A remote code execution vulnerability in MSHTML Engine can be exploited remotely via specially crafted file to execute arbitrary code;
  4. An elevation of privilege vulnerability in Microsoft SharePoint can be exploited remotely via specially crafted webpage to gain privileges;
  5. A cross-site-scripting (XSS) vulnerability Microsoft Office SharePoint can be exploited remotely via specially crafted webpage to spoof user interface;
  6. A cross-site-scripting (XSS) vulnerability Microsoft Office SharePoint can be exploited remotely via specially crafted webpage to spoof user interface;
  7. An elevation of privilege vulnerability in Skype for Android can be exploited remotely via specially designed request to gain privileges;
  8. A remote code execution vulnerability in Microsoft Word can be exploited remotely via specially crafted file to execute arbitrary code;
  9. A cross-site-scripting (XSS) vulnerability Microsoft Office SharePoint can be exploited remotely via specially crafted webpage to spoof user interface;
  10. An information disclosure vulnerability in Microsoft Word can be exploited remotely via specially designed document file to obtain sensitive information;

Oficiální doporučení

Vykořisťování

Public exploits exist for this vulnerability.

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Související produkty

seznam CVE

  • CVE-2019-0582
    critical
  • CVE-2019-0538
    critical
  • CVE-2019-0560
    high
  • CVE-2019-0559
    high
  • CVE-2019-0541
    critical
  • CVE-2019-0562
    high
  • CVE-2019-0556
    high
  • CVE-2019-0558
    high
  • CVE-2019-0622
    warning
  • CVE-2019-0585
    critical
  • CVE-2019-0557
    high
  • CVE-2019-0561
    high

seznam KB

Zobrazit více

Zjistěte statistiky zranitelností šířících se ve vaší oblasti statistics.securelist.com

Našli jste v popisu této chyby zabezpečení nepřesnost? Dej nám vědět!
Kaspersky Next
Let’s go Next: redefine your business’s cybersecurity
Zjistěte více
Kaspersky Premium
Zjistěte více
Do you want to save your changes?
Your message has been sent successfully.