CVE-2019-0669

Description

An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka Microsoft Excel Information Disclosure Vulnerability.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
25.751

Associated Vulnerability

VulnerabilityOS Platform
Microsoft Excel Information Disclosure Vulnerability for Microsoft Office Excel Viewer 2007 (KB4461608)Windows
Microsoft Excel Information Disclosure Vulnerability for Microsoft Office Compatibility Pack Service Pack 3 (KB4461607)Windows
Microsoft Excel Information Disclosure Vulnerability for Microsoft Office 2010 (KB4462177) 32-Bit EditionWindows
Microsoft Excel Information Disclosure Vulnerability for Microsoft Office 2010 (KB4462177) 64-Bit EditionWindows
Microsoft Excel Information Disclosure Vulnerability for Microsoft Excel 2010 (KB4462186) 64-Bit EditionWindows
Microsoft Excel Information Disclosure Vulnerability for Microsoft Excel 2010 (KB4462186) 32-Bit EditionWindows
Microsoft Excel Information Disclosure Vulnerability for Microsoft Excel 2016 (KB4462115) 32-Bit EditionWindows
Microsoft Excel Information Disclosure Vulnerability for Microsoft Excel 2016 (KB4462115) 64-Bit EditionWindows
Microsoft Excel Information Disclosure Vulnerability for Microsoft Excel 2013 (KB4461597) 64-Bit EditionWindows
Microsoft Excel Information Disclosure Vulnerability for Microsoft Excel 2013 (KB4461597) 32-Bit EditionWindows
Jet Database Engine Remote Code Execution Vulnerability for Office 365 Professional Plus Semi-Annual Channel Version 1708 (Build 8431.2372)Windows
Jet Database Engine Remote Code Execution Vulnerability for Office 365 Professional Plus Semi-Annual Channel Version 1708 (Build 8431.2372)Windows
Update for Office 365 Business Edition Semi-Annual Channel Version 1708 (Build 8431.2372)Windows
Update for Office 365 Business Edition Semi-Annual Channel Version 1708 (Build 8431.2372)Windows
Jet Database Engine Remote Code Execution Vulnerability for Office 365 Professional Plus Monthly Channel Version 1708 (Build 8431.2372)Windows
Jet Database Engine Remote Code Execution Vulnerability for Office 365 Professional Plus Monthly Channel Version 1708 (Build 8431.2372)Windows
Jet Database Engine Remote Code Execution Vulnerability for Office 365 Business Edition Monthly Channel Version 1708 (Build 8431.2372)Windows
Jet Database Engine Remote Code Execution Vulnerability for Office 365 Business Edition Monthly Channel Version 1708 (Build 8431.2372)Windows
Jet Database Engine Remote Code Execution Vulnerability for Office 365 Professional Plus Semi-Annual Channel Version 1803 (Build 9126.2356)Windows
Jet Database Engine Remote Code Execution Vulnerability for Office 365 Professional Plus Semi-Annual Channel Version 1803 (Build 9126.2356)Windows
Jet Database Engine Remote Code Execution Vulnerability for Office 365 Business Edition Semi-Annual Channel Version 1803 (Build 9126.2356)Windows
Jet Database Engine Remote Code Execution Vulnerability for Office 365 Business Edition Semi-Annual Channel Version 1803 (Build 9126.2356)Windows
Jet Database Engine Remote Code Execution Vulnerability for Office 365 Professional Plus Semi-Annual-Targeted Channel Version 1808 (Build 10730.20280)Windows
Jet Database Engine Remote Code Execution Vulnerability for Office 365 Professional Plus Semi-Annual-Targeted Channel Version 1808 (Build 10730.20280)Windows
Jet Database Engine Remote Code Execution Vulnerability for Office 365 Professional Plus Semi-Annual Channel Version 1808 (Build 10730.20280)Windows
Jet Database Engine Remote Code Execution Vulnerability for Office 365 Professional Plus Semi-Annual Channel Version 1808 (Build 10730.20280)Windows
Update for Office 365 Business Edition Semi-Annual Channel Version 1808 (Build 10730.20280)Windows
Update for Office 365 Business Edition Semi-Annual Channel Version 1808 (Build 10730.20280)Windows
Jet Database Engine Remote Code Execution Vulnerability for Office 365 Professional Plus Monthly Channel Version 1901 (Build 11231.20174)Windows
Jet Database Engine Remote Code Execution Vulnerability for Office 365 Professional Plus Monthly Channel Version 1901 (Build 11231.20174)Windows
Jet Database Engine Remote Code Execution Vulnerability for Office 365 Business Edition Monthly Channel Version 1901 (Build 11231.20174)Windows
Jet Database Engine Remote Code Execution Vulnerability for Office 365 Business Edition Monthly Channel Version 1901 (Build 11231.20174)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-26196Security Update for Microsoft Office Excel Viewer 2007 (KB4461608)
PATCH-26101Security Update for Microsoft Office Compatibility Pack Service Pack 3 (KB4461607)
PATCH-26081Security Update for Microsoft Excel 2010 (KB4462186) 64-Bit Edition
PATCH-26082Security Update for Microsoft Excel 2010 (KB4462186) 32-Bit Edition
PATCH-26097Security Update for Microsoft Excel 2016 (KB4462115) 32-Bit Edition
PATCH-26098Security Update for Microsoft Excel 2016 (KB4462115) 64-Bit Edition
PATCH-26091Security Update for Microsoft Excel 2013 (KB4461597) 64-Bit Edition
PATCH-26092Security Update for Microsoft Excel 2013 (KB4461597) 32-Bit Edition
PATCH-26245Update for Office 365 Professional Plus Semi-Annual Channel Version 1708 (Build 8431.2372)
PATCH-26247Update for Office 365 Professional Plus Semi-Annual Channel Version 1708 (Build 8431.2372)
PATCH-26382Update for Office 365 Professional Plus Monthly Channel Version 1708 (Build 8431.2372)
PATCH-26384Update for Office 365 Professional Plus Monthly Channel Version 1708 (Build 8431.2372)
PATCH-26386Update for Office 365 Business Edition Monthly Channel Version 1708 (Build 8431.2372)
PATCH-26388Update for Office 365 Business Edition Monthly Channel Version 1708 (Build 8431.2372)
PATCH-26237Update for Office 365 Professional Plus Semi-Annual Channel Version 1803 (Build 9126.2356)
PATCH-26239Update for Office 365 Professional Plus Semi-Annual Channel Version 1803 (Build 9126.2356)
PATCH-26241Update for Office 365 Business Edition Semi-Annual Channel Version 1803 (Build 9126.2356)
PATCH-26243Update for Office 365 Business Edition Semi-Annual Channel Version 1803 (Build 9126.2356)
PATCH-23950Update for Office 365 Professional Plus Semi-Annual-Targeted Channel Version 1808 (Build 10730.20280)
PATCH-23952Update for Office 365 Professional Plus Semi-Annual-Targeted Channel Version 1808 (Build 10730.20280)
PATCH-26229Update for Office 365 Professional Plus Semi-Annual Channel Version 1808 (Build 10730.20280)
PATCH-26231Update for Office 365 Professional Plus Semi-Annual Channel Version 1808 (Build 10730.20280)
PATCH-26221Update for Office 365 Professional Plus Monthly Channel Version 1901 (Build 11231.20174)
PATCH-26223Update for Office 365 Professional Plus Monthly Channel Version 1901 (Build 11231.20174)
PATCH-26225Update for Office 365 Business Edition Monthly Channel Version 1901 (Build 11231.20174)
PATCH-26227Update for Office 365 Business Edition Monthly Channel Version 1901 (Build 11231.20174)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234