CVE-2019-1264

Description

A security feature bypass vulnerability exists when Microsoft Office improperly handles input, aka Microsoft Office Security Feature Bypass Vulnerability.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
7.973

Associated Vulnerability

VulnerabilityOS Platform
Microsoft Office Security Feature Bypass Vulnerability for Microsoft Project 2010 (KB4461631) 32-Bit EditionWindows
Microsoft Office Security Feature Bypass Vulnerability for Microsoft Project 2010 (KB4461631) 64-Bit EditionWindows
Microsoft Office Security Feature Bypass Vulnerability for Microsoft Project 2016 (KB4475589) 64-Bit EditionWindows
Microsoft Office Security Feature Bypass Vulnerability for Microsoft Project 2016 (KB4475589) 32-Bit EditionWindows
Microsoft Office Security Feature Bypass Vulnerability for Microsoft Project 2013 (KB4464548) 64-Bit EditionWindows
Microsoft Office Security Feature Bypass Vulnerability for Microsoft Office 2016 (KB4475583) 32-Bit EditionWindows
Microsoft Office Security Feature Bypass Vulnerability for Microsoft Office 2016 (KB4475583) 64-Bit EditionWindows
Microsoft Office Security Feature Bypass Vulnerability for Microsoft Office 2013 (KB4475607) 32-Bit EditionWindows
Microsoft Office Security Feature Bypass Vulnerability for Microsoft Office 2013 (KB4475607) 64-Bit EditionWindows
Microsoft Office Security Feature Bypass Vulnerability for Microsoft Office 2010 (KB4464566) 32-Bit EditionWindows
Microsoft Office Security Feature Bypass Vulnerability for Microsoft Office 2010 (KB4464566) 64-Bit EditionWindows
Microsoft Office Security Feature Bypass Vulnerability for Microsoft Project 2013 (KB4464548) 32-Bit EditionWindows
Microsoft Office Security Feature Bypass Vulnerability for Office 365 Professional Plus Semi Annual Channel for x64 1902 of version(11328.20420)Windows
Microsoft Office Security Feature Bypass Vulnerability for Office 365 Professional Plus Semi Annual Channel for x86 1902 of version(11328.20420)Windows
Microsoft Office Security Feature Bypass Vulnerability for Office 365 Business Edition Semi Annual Channel for x64 1902 of version(11328.20420)Windows
Microsoft Office Security Feature Bypass Vulnerability for Office 365 Business Edition Semi Annual Channel for x86 1902 of version(11328.20420)Windows
Microsoft Office Security Feature Bypass Vulnerability for Office 365 Professional Plus Monthly Channel for x64 1908 of version(11929.20300)Windows
Microsoft Office Security Feature Bypass Vulnerability for Office 365 Professional Plus Monthly Channel for x86 1908 of version(11929.20300)Windows
Microsoft Office Security Feature Bypass Vulnerability for Office 365 Business Edition Monthly Channel for x64 1908 of version(11929.20300)Windows
Microsoft Office Security Feature Bypass Vulnerability for Office 365 Business Edition Monthly Channel for x86 1908 of version(11929.20300)Windows
Microsoft Office Security Feature Bypass Vulnerability for Office 365 Professional Plus Semi Annual Targeted Channel for x64 1908 of version(11929.20300)Windows
Microsoft Office Security Feature Bypass Vulnerability for Office 365 Professional Plus Semi Annual Targeted Channel for x86 1908 of version(11929.20300)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-27493Security Update for Microsoft Project 2016 (KB4475589) 64-Bit Edition
PATCH-27494Security Update for Microsoft Project 2016 (KB4475589) 32-Bit Edition
PATCH-27487Security Update for Microsoft Project 2013 (KB4464548) 64-Bit Edition
PATCH-27491Security Update for Microsoft Office 2016 (KB4475583) 32-Bit Edition
PATCH-27492Security Update for Microsoft Office 2016 (KB4475583) 64-Bit Edition
PATCH-27486Security Update for Microsoft Office 2013 (KB4475607) 32-Bit Edition
PATCH-27499Security Update for Microsoft Office 2013 (KB4475607) 64-Bit Edition
PATCH-27476Security Update for Microsoft Office 2010 (KB4464566) 32-Bit Edition
PATCH-27477Security Update for Microsoft Office 2010 (KB4464566) 64-Bit Edition
PATCH-27536Security Update for Microsoft Project 2013 (KB4464548) 32-Bit Edition
PATCH-27513Update for Office 365 Professional Plus Semi Annual Channel for x64 1902 of version(11328.20420)
PATCH-27515Update for Office 365 Professional Plus Semi Annual Channel for x86 1902 of version(11328.20420)
PATCH-27517Update for Office 365 Business Edition Semi Annual Channel for x64 1902 of version(11328.20420)
PATCH-27519Update for Office 365 Business Edition Semi Annual Channel for x86 1902 of version(11328.20420)
PATCH-27505Update for Office 365 Professional Plus Monthly Channel for x64 1908 of version(11929.20300)
PATCH-27507Update for Office 365 Professional Plus Monthly Channel for x86 1908 of version(11929.20300)
PATCH-27509Update for Office 365 Business Edition Monthly Channel for x64 1908 of version(11929.20300)
PATCH-27511Update for Office 365 Business Edition Monthly Channel for x86 1908 of version(11929.20300)
PATCH-27521Update for Office 365 Professional Plus Semi Annual Targeted Channel for x64 1908 of version(11929.20300)
PATCH-27523Update for Office 365 Professional Plus Semi Annual Targeted Channel for x86 1908 of version(11929.20300)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234