KLA11434
Multiple vulnerabilities in Microsoft Office

Обновлено: 03/06/2020
Дата обнаружения
12/03/2019
Уровень угрозы
High
Описание

Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to execute arbitrary code, spoof user interface.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Microsoft Office Access Connectivity Engine can be exploited remotely via specially crafted file to execute arbitrary code.
  2. A spoofing vulnerability in Skype for Business and Lync can be exploited remotely via specially crafted request to spoof user interface.
  3. A cross-site-scripting (XSS) vulnerability Microsoft Office SharePoint can be exploited remotely via specially crafted web to spoof user interface.
Пораженные продукты

Microsoft Office 2010 Service Pack 2 (64-bit editions)
Microsoft Office 2010 Service Pack 2 (32-bit editions)
Skype for Business Server 2015 March 2019 Update
Microsoft Lync Server 2013 July 2018 Update
Microsoft SharePoint Enterprise Server 2016
Microsoft SharePoint Foundation 2013 Service Pack 1

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2019-0748
CVE-2019-0798
CVE-2019-0778
Оказываемое влияние
?
ACE 
[?]

SUI 
[?]
Связанные продукты
Microsoft Lync
Microsoft Office
Microsoft Lync Server
CVE-IDS
CVE-2019-07489.3Critical
CVE-2019-07984.3Warning
CVE-2019-07783.5Warning