CVE-2019-1109 is a critical spoofing vulnerability affecting Microsoft Office and Office 365. It arises from insufficient validation of web pages making requests to Office documents by Microsoft Office Javascript. Successful exploitation allows an attacker to read or write information within Office documents. This vulnerability has a CVSS score of 9.1 (Critical), indicating a high-impact, easily exploitable flaw (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). The attack does not require user interaction or prior authentication. While not listed in CISA's KEV catalog, and with no public exploit code (Metasploit, Nuclei, ExploitDB) available, it has garnered significant community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2013:sp1:*:*:rt:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:office_365:-:*:*:*:proplus:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.