CVE-2019-0822 is a remote code execution vulnerability within Microsoft Graphics Components, specifically affecting Microsoft Office and Office 365 ProPlus. This vulnerability carries a high CVSS score of 7.8, indicating a significant risk due to its potential for complete compromise of confidentiality, integrity, and availability, though it requires user interaction to exploit. While the FAUCET Risk Score is high at 91/100, there is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog. Community discussion and media coverage are minimal, with only one article from BleepingComputer mentioning its fix in a 2019 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2016:*:*:*:*:mac_os_x:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2019:*:*:*:*:macos:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:office_365_proplus:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.