CVE-2019-1205 is a remote code execution vulnerability in Microsoft Word that affects Microsoft Office, Office 365 ProPlus, Office Online Server, and SharePoint Server. An attacker could exploit this by convincing a user to open a specially crafted file, potentially through email attachments or malicious websites, or by rendering a crafted email in the Outlook Preview Pane. Successful exploitation grants the attacker the same permissions as the logged-on user, allowing for high impact to confidentiality, integrity, and availability. While not actively exploited (KEV: No) and lacking public exploit code (Metasploit, Nuclei, ExploitDB: None), it has a high CVSS score of 7.8 and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2016:*:*:*:*:mac_os:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2019:*:*:*:*:macos:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:office_365_proplus:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:office_online_server:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.