CVE-2019-1109 Vulnerability Details

  /     /     /  

CVE-2019-1109 Metadata Quick Info

CVE Published: 29/07/2019 | CVE Updated: 04/08/2024 | CVE Year: 2019
Source: microsoft | Vendor: Microsoft | Product: Microsoft Office
Status : PUBLISHED

CVE-2019-1109 Description

A spoofing vulnerability exists when Microsoft Office Javascript does not check the validity of the web page making a request to Office documents.An attacker who successfully exploited this vulnerability could read or write information in Office documents.The security update addresses the vulnerability by correcting the way that Microsoft Office Javascript verifies trusted web pages., aka \'Microsoft Office Spoofing Vulnerability\'.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Spoofing
Source: Microsoft

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).