CVE-2019-0540: Medium severity microsoft office excel viewer vulnerability
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-0540?
CVE-2019-0540 is a security feature bypass vulnerability in Microsoft Office that allows attackers to trick victims into entering credentials.
How does CVE-2019-0540 work?
CVE-2019-0540 works by exploiting Microsoft Office's failure to validate URLs, enabling attackers to send specially crafted files to victims.
Which software is affected by CVE-2019-0540?
Microsoft Excel Viewer, Microsoft Office 2010 SP2, Microsoft Office 2013, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 Proplus, Microsoft PowerPoint Viewer, and Microsoft Word Viewer are affected by CVE-2019-0540.
What is the severity of CVE-2019-0540?
CVE-2019-0540 has a severity rating of 5.5, which is considered medium.
How can I mitigate CVE-2019-0540?
To mitigate CVE-2019-0540, it is recommended to apply the latest security updates provided by Microsoft.