CVE-2019-1264: Input Validation
Published Sep 11, 2019
·Updated
A security feature bypass vulnerability exists when Microsoft Office improperly handles input, aka 'Microsoft Office Security Feature Bypass Vulnerability'.
Affected Software
9 affected components
Microsoft Office=2010-sp2
Microsoft Office=2013-sp1
Microsoft Office=2013-sp1
Microsoft Office=2016
Microsoft Office=2019
Microsoft Office 365 ProPlus
Microsoft Project=2010-sp2
Microsoft Project=2013-sp1
Microsoft Project=2016
Remediation
Event History
Sep 11, 2019
CVE Published
via MITRE·09:24 PM
Data Sourced
via MITRE·09:24 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-1264?
CVE-2019-1264 is a security feature bypass vulnerability that exists in Microsoft Office.
2
What is the severity of CVE-2019-1264?
The severity of CVE-2019-1264 is high, with a CVSS score of 7.8.
3
Which versions of Microsoft Office are affected by CVE-2019-1264?
CVE-2019-1264 affects Microsoft Office 2010 SP2, 2013 SP1, 2016, and 2019, as well as Microsoft Office 365 Proplus.
4
How can I fix CVE-2019-1264?
To fix CVE-2019-1264, apply the security updates provided by Microsoft.
5
Where can I find more information about CVE-2019-1264?
You can find more information about CVE-2019-1264 on the Microsoft Security Guidance Advisory page: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1264