CVE-2019-0675 is a remote code execution vulnerability affecting the Microsoft Office Access Connectivity Engine, allowing attackers to execute arbitrary code due to improper memory handling. With a CVSS score of 7.8 (High), it requires user interaction (UI:R) but has low attack complexity (AC:L), potentially leading to complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). While it has a high FAUCET Risk Score of 94/100 and an EPSS score indicating it's more exploitable than 96.56% of CVEs, there is currently no public exploit code (Metasploit, Nuclei, ExploitDB) and it is not listed in CISA's KEV catalog. Community discussion and media coverage are minimal, suggesting limited public awareness or active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.