CVE-2019-1112 is an information disclosure vulnerability in Microsoft Excel and Office 365 ProPlus, allowing the improper disclosure of memory contents. This medium-severity vulnerability (CVSS 5.5) requires user interaction (UI:R) and local access (AV:L) to achieve high confidentiality impact (C:H). While not actively exploited or listed in CISA's KEV catalog, there is no public exploit code available, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:office_365_proplus:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.