Medium severity5.5NVD Advisory· Published Mar 5, 2019· Updated Jun 17, 2026
CVE-2019-0540
CVE-2019-0540
Description
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'.
Affected products
15cpe:2.3:a:microsoft:excel_viewer:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microsoft:excel_viewer:-:*:*:*:*:*:*:*
- (no CPE)range: unspecified
cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2013:*:*:*:rt:*:*:*
- cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:*
- (no CPE)
cpe:2.3:a:microsoft:office_365_proplus:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microsoft:office_365_proplus:-:*:*:*:*:*:*:*
- (no CPE)range: 32-bit Systems
cpe:2.3:a:microsoft:powerpoint_viewer:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microsoft:powerpoint_viewer:-:*:*:*:*:*:*:*
- (no CPE)range: unspecified
- cpe:2.3:a:microsoft:word_viewer:-:*:*:*:*:*:*:*
- Range: 2010 Service Pack 2 (32-bit editions)
- Range: Service Pack 3
Patches
Vulnerability mechanics
References
2- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0540nvdPatchVendor Advisory
- www.securityfocus.com/bid/106863nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.