KLA11617
Multiple vulnerabilities in Microsoft Office

Updated: 06/03/2020
Detect date
?
12/10/2019
Severity
?
High
Description

Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to execute arbitrary code, obtain sensitive information, spoof user interface.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Microsoft PowerPoint can be exploited remotely via specially crafted file to execute arbitrary code.
  2. An information disclosure vulnerability in Microsoft Access can be exploited remotely via specially crafted application to obtain sensitive information.
  3. An information disclosure vulnerability in Microsoft Excel can be exploited remotely.
  4. A remote code execution vulnerability in Microsoft Word can be exploited remotely via specially crafted file to execute arbitrary code.
  5. A spoofing vulnerability in Skype for Business Server can be exploited remotely via specially crafted request to spoof user interface.
Affected products

Microsoft Word 2013 Service Pack 1 (64-bit editions)
Microsoft PowerPoint 2013 Service Pack 1 (32-bit editions)
Microsoft Word 2013 Service Pack 1 (32-bit editions)
Microsoft PowerPoint 2013 Service Pack 1 (64-bit editions)
Microsoft Excel 2013 RT Service Pack 1
Microsoft Word 2010 Service Pack 2 (32-bit editions)
Microsoft Office 2013 Service Pack 1 (64-bit editions)
Microsoft Excel 2013 Service Pack 1 (64-bit editions)
Microsoft Excel 2016 (32-bit edition)
Microsoft Word 2016 (64-bit edition)
Microsoft Word 2013 RT Service Pack 1
Microsoft Office 2016 (32-bit edition)
Microsoft Excel 2010 Service Pack 2 (64-bit editions)
Microsoft Excel 2016 (64-bit edition)
Microsoft Office 2013 RT Service Pack 1
Microsoft Office 2010 Service Pack 2 (32-bit editions)
Microsoft PowerPoint 2016 (32-bit edition)
Microsoft PowerPoint 2013 RT Service Pack 1
Office 365 ProPlus for 64-bit Systems
Microsoft Office 2019 for Mac
Office 365 ProPlus for 32-bit Systems
Microsoft Word 2016 (32-bit edition)
Microsoft Office 2016 (64-bit edition)
Microsoft Excel 2010 Service Pack 2 (32-bit editions)
Microsoft Office 2013 Service Pack 1 (32-bit editions)
Microsoft Word 2010 Service Pack 2 (64-bit editions)
Microsoft Office 2016 for Mac
Microsoft PowerPoint 2016 (64-bit edition)
Microsoft Excel 2013 Service Pack 1 (32-bit editions)
Skype for Business Server 2019 CU2
Microsoft PowerPoint 2010 Service Pack 2 (64-bit editions)
Microsoft Office 2019 for 64-bit editions
Microsoft Office 2019 for 32-bit editions
Microsoft Office 2010 Service Pack 2 (64-bit editions)
Microsoft PowerPoint 2010 Service Pack 2 (32-bit editions)

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2019-1462
CVE-2019-1400
CVE-2019-1464
CVE-2019-1461
CVE-2019-1490
CVE-2019-1463

Impacts
?
ACE 
[?]

OSI 
[?]

SUI 
[?]
Related products
Microsoft Office
Microsoft Excel
Microsoft Word
CVE-IDS
?
CVE-2019-14629.3Critical
CVE-2019-14002.1Warning
CVE-2019-14644.3Warning
CVE-2019-14617.1High
CVE-2019-14903.5Warning
CVE-2019-14632.1Warning
Microsoft official advisories
Microsoft Security Update Guide
KB list

4484192
4484094
4461590
4534761
4484193
4484169
4484179
4475598
4484182
4484190
4484196
4484184
4484186
4461613
4484180
4475601
4484166

Find out the statistics of the vulnerabilities spreading in your region