Searching
..

Click anywhere to stop

KLA11617
Multiple vulnerabilities in Microsoft Office

Обновлено: 22/01/2024
Дата обнаружения
10/12/2019
Уровень угрозы
High
Описание

Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to execute arbitrary code, obtain sensitive information, spoof user interface.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Microsoft PowerPoint can be exploited remotely via specially crafted file to execute arbitrary code.
  2. An information disclosure vulnerability in Microsoft Access can be exploited remotely via specially crafted application to obtain sensitive information.
  3. An information disclosure vulnerability in Microsoft Excel can be exploited remotely.
  4. A remote code execution vulnerability in Microsoft Word can be exploited remotely via specially crafted file to execute arbitrary code.
  5. A spoofing vulnerability in Skype for Business Server can be exploited remotely via specially crafted request to spoof user interface.
Пораженные продукты

Microsoft Word 2013 Service Pack 1 (64-bit editions)
Microsoft PowerPoint 2013 Service Pack 1 (32-bit editions)
Microsoft Word 2013 Service Pack 1 (32-bit editions)
Microsoft PowerPoint 2013 Service Pack 1 (64-bit editions)
Microsoft Excel 2013 RT Service Pack 1
Microsoft Word 2010 Service Pack 2 (32-bit editions)
Microsoft Office 2013 Service Pack 1 (64-bit editions)
Microsoft Excel 2013 Service Pack 1 (64-bit editions)
Microsoft Excel 2016 (32-bit edition)
Microsoft Word 2016 (64-bit edition)
Microsoft Word 2013 RT Service Pack 1
Microsoft Office 2016 (32-bit edition)
Microsoft Excel 2010 Service Pack 2 (64-bit editions)
Microsoft Excel 2016 (64-bit edition)
Microsoft Office 2013 RT Service Pack 1
Microsoft Office 2010 Service Pack 2 (32-bit editions)
Microsoft PowerPoint 2016 (32-bit edition)
Microsoft PowerPoint 2013 RT Service Pack 1
Office 365 ProPlus for 64-bit Systems
Microsoft Office 2019 for Mac
Office 365 ProPlus for 32-bit Systems
Microsoft Word 2016 (32-bit edition)
Microsoft Office 2016 (64-bit edition)
Microsoft Excel 2010 Service Pack 2 (32-bit editions)
Microsoft Office 2013 Service Pack 1 (32-bit editions)
Microsoft Word 2010 Service Pack 2 (64-bit editions)
Microsoft Office 2016 for Mac
Microsoft PowerPoint 2016 (64-bit edition)
Microsoft Excel 2013 Service Pack 1 (32-bit editions)
Skype for Business Server 2019 CU2
Microsoft PowerPoint 2010 Service Pack 2 (64-bit editions)
Microsoft Office 2019 for 64-bit editions
Microsoft Office 2019 for 32-bit editions
Microsoft Office 2010 Service Pack 2 (64-bit editions)
Microsoft PowerPoint 2010 Service Pack 2 (32-bit editions)

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2019-1462
CVE-2019-1400
CVE-2019-1464
CVE-2019-1461
CVE-2019-1490
CVE-2019-1463
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

SUI 
[?]
Связанные продукты
Microsoft Office
Microsoft Excel
Microsoft Word
CVE-IDS
CVE-2019-14629.3Critical
CVE-2019-14002.1Warning
CVE-2019-14644.3Warning
CVE-2019-14617.1High
CVE-2019-14903.5Warning
CVE-2019-14632.1Warning