CVE-2019-1297 is a remote code execution vulnerability in Microsoft Excel, Microsoft Office, and Office 365 ProPlus, stemming from improper memory object handling. This high-severity vulnerability (CVSS 8.8) can be exploited remotely with low attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, as indicated by its presence in the KEV catalog, and has garnered significant community discussion and media coverage. While no public exploit code is listed for Metasploit, Nuclei, or ExploitDB, its active exploitation underscores the critical need for patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2010:sp2:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2013:sp1:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2013:sp1:*:*:rt:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2016:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.