CVE-2019-1199 is a remote code execution vulnerability in Microsoft Outlook and Office 365 ProPlus, stemming from improper memory object handling. It carries a CVSS score of 7.8 (HIGH) and a FAUCET Risk Score of 81/100, indicating significant severity. Exploitation requires user interaction, typically opening a specially crafted file, and can lead to arbitrary code execution in the context of the current user, potentially allowing full system control if the user has administrative rights. While the Preview Pane can be an attack vector, there is no evidence of active exploitation, nor are there known public exploits in Metasploit or ExploitDB, despite moderate community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:office_365_proplus:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.