CVE-2019-1462: Microsoft PowerPoint PPT File Use-After-Free Remote Code Execution Vulnerability
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka 'Microsoft PowerPoint Remote Code Execution Vulnerability'.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft PowerPoint. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PowerPoint presentation files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-1462?
CVE-2019-1462 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Microsoft PowerPoint.
How does CVE-2019-1462 work?
CVE-2019-1462 is a use-after-free vulnerability that exists within the processing of PowerPoint PPT files. By visiting a malicious page or opening a malicious PPT file, an attacker can exploit this vulnerability and execute arbitrary code.
What software is affected by CVE-2019-1462?
CVE-2019-1462 affects Microsoft PowerPoint versions 2010 SP2, 2013 SP1, 2016, Microsoft Office 2016 for Mac, Microsoft Office 2019, Microsoft Office 2019 for macOS, and Microsoft Office 365 ProPlus.
How severe is CVE-2019-1462?
The severity of CVE-2019-1462 is critical, with a CVSSv3 score of 7.8.
How can I mitigate CVE-2019-1462?
To mitigate CVE-2019-1462, apply the necessary security updates provided by Microsoft. Additionally, be cautious when opening PPT files from untrusted sources.