CVE-2019-1457 is a security feature bypass vulnerability in Microsoft Office Excel that allows macros to execute even when macro settings are configured to prevent them. This vulnerability carries a CVSS score of 7.8 (High), indicating a significant risk where an attacker could achieve high confidentiality, integrity, and availability impacts through a low-complexity attack requiring user interaction. While not listed in CISA's KEV catalog, its EPSS score suggests a moderate likelihood of exploitation. There is no public exploit code available in Metasploit, Nuclei, or ExploitDB, and community discussion and media coverage are limited, suggesting it is not widely exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2016:*:*:*:*:mac_os:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2019:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.