First published: Wed Sep 11 2019(Updated: )
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Excel | =2010-sp2 | |
Microsoft Excel | =2013-sp1 | |
Microsoft Excel | =2013-sp1 | |
Microsoft Excel | =2016 | |
Microsoft Office Mac Os | =2016 | |
Microsoft Office | =2019 | |
Microsoft Office | =2019 | |
Microsoft Office 365 Proplus | ||
Microsoft Excel | ||
=2010-sp2 | ||
=2013-sp1 | ||
=2013-sp1 | ||
=2016 | ||
=2016 | ||
=2019 | ||
=2019 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1297 is a remote code execution vulnerability in Microsoft Excel software.
Microsoft Excel 2010 SP2, Microsoft Excel 2013 SP1, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, and Microsoft Office 365 Proplus are affected by CVE-2019-1297.
The severity of CVE-2019-1297 is critical with a CVSS score of 8.8.
CVE-2019-1297 allows an attacker to execute arbitrary code on a target system by exploiting a vulnerability in how Microsoft Excel handles objects in memory.
Yes, Microsoft has released security updates to address the vulnerability. Users should update their software to the latest available version.