VYPR
High severity8.8NVD Advisory· Published Jan 8, 2019· Updated Jun 17, 2026

CVE-2019-0585

CVE-2019-0585

Description

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Microsoft SharePoint, Microsoft Office Online Server, Microsoft Word, Microsoft SharePoint Server.

Affected products

27
  • Microsoft/Office6 versions
    cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:office:2016:*:*:*:*:mac_os_x:*:*
    • cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:office:2019:*:*:*:*:macos:*:*
    • (no CPE)
    • (no CPE)range: 365 ProPlus for 32-bit Systems
  • cpe:2.3:a:microsoft:office_365_proplus:-:*:*:*:*:*:*:*
  • cpe:2.3:a:microsoft:office_online_server:-:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:microsoft:office_online_server:-:*:*:*:*:*:*:*
    • (no CPE)range: Microsoft Office Online Server
  • cpe:2.3:a:microsoft:office_web_apps_server:2010:sp2:*:*:*:*:*:*
  • cpe:2.3:a:microsoft:office_word_viewer:-:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:microsoft:office_word_viewer:-:*:*:*:*:*:*:*
    • (no CPE)range: Microsoft Office Word Viewer
  • cpe:2.3:a:microsoft:sharepoint_server:2013:sp1:*:*:enterprise:*:*:*+ 4 more
    • cpe:2.3:a:microsoft:sharepoint_server:2013:sp1:*:*:enterprise:*:*:*
    • cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
    • cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: 2019
  • Microsoft/Word7 versions
    cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:word:2013:sp1:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:word:2013:sp1:*:*:rt:*:*:*
    • cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: 2010 Service Pack 2 (32-bit editions)
    • (no CPE)range: Automation Services on Microsoft SharePoint Server 2010 Service Pack 2
  • cpe:2.3:a:microsoft:word_automation_services:-:*:*:*:*:*:*:*
  • Range: 2010 Service Pack 2 (32-bit editions)
  • Range: Enterprise Server 2013 Service Pack 1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.