CVE Database
/

CVE-2019-1109

Back to search

CVE-2019-1109

Published: Jul 29, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

A spoofing vulnerability exists when Microsoft Office Javascript does not check the validity of the web page making a request to Office documents.An attacker who successfully exploited this vulnerability could read or write information in Office documents.The security update addresses the vulnerability by correcting the way that Microsoft Office Javascript verifies trusted web pages., aka 'Microsoft Office Spoofing Vulnerability'.

VendorProductVersions

Microsoft

Microsoft Office

affected
2013 Service Pack 1 (32-bit editions)
affected
2013 Service Pack 1 (64-bit editions)
affected
2013 RT Service Pack 1
affected
2016 (32-bit edition)
affected
2016 (64-bit edition)

+2 more versions

Microsoft

Office 365 ProPlus

affected
32-bit Systems
affected
64-bit Systems

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now