CVE-2019-1442 is a security feature bypass vulnerability in Microsoft Office, specifically affecting Microsoft SharePoint Server, where the software fails to properly validate URLs. This flaw allows an attacker to craft a malicious file that, when opened by a victim, could trick them into divulging credentials. With a CVSS score of 5.5 (MEDIUM), it requires user interaction and local access, but successful exploitation could lead to high integrity impact. There is no evidence of active exploitation, nor are there public exploits available in Metasploit, Nuclei, or ExploitDB, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.