CVE-2019-1402: Infoleak
Published Nov 12, 2019
·Updated
An information disclosure vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Information Disclosure Vulnerability'.
Affected Software
6 affected components
Microsoft Office=2010-sp2
Microsoft Office=2013-sp1
Microsoft Office=2013-sp1
Microsoft Office=2016
Microsoft Office=2019
Microsoft Office 365
Remediation
Event History
Nov 12, 2019
CVE Published
via MITRE·06:53 PM
Data Sourced
via MITRE·06:53 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-1402?
CVE-2019-1402 is an information disclosure vulnerability in Microsoft Office software.
2
How does the vulnerability in CVE-2019-1402 occur?
The vulnerability occurs when the software fails to properly handle objects in memory.
3
Which versions of Microsoft Office are affected by CVE-2019-1402?
Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Office 2019, and Microsoft Office 365 ProPlus are affected.
4
What is the severity of CVE-2019-1402?
CVE-2019-1402 has a severity rating of medium (CVSS score of 5.5).
5
How can I fix CVE-2019-1402?
Apply the latest security updates provided by Microsoft to fix CVE-2019-1402.