KLA11434
Multiple vulnerabilities in Microsoft Office
Updated: 05/22/2020
Microsoft official advisories
Microsoft Security Update Guide
KB list

3061064
2809243
4462211
4462226
4462208

Detect date
?
03/12/2019
Severity
?
High
Description

Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to execute arbitrary code, spoof user interface.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Microsoft Office Access Connectivity Engine can be exploited remotely via specially crafted file to execute arbitrary code.
  2. A spoofing vulnerability in Skype for Business and Lync can be exploited remotely via specially crafted request to spoof user interface.
  3. A cross-site-scripting (XSS) vulnerability Microsoft Office SharePoint can be exploited remotely via specially crafted web to spoof user interface.
Affected products

Microsoft Office 2010 Service Pack 2 (64-bit editions)
Microsoft Office 2010 Service Pack 2 (32-bit editions)
Skype for Business Server 2015 March 2019 Update
Microsoft Lync Server 2013 July 2018 Update
Microsoft SharePoint Enterprise Server 2016
Microsoft SharePoint Foundation 2013 Service Pack 1

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2019-0748
CVE-2019-0798
CVE-2019-0778

Impacts
?
ACE 
[?]

SUI 
[?]
Related products
Microsoft Lync
Microsoft Office
Microsoft Lync Server
CVE-IDS
?
CVE-2019-07480.0Unknown
CVE-2019-07980.0Unknown
CVE-2019-07780.0Unknown