VYPR
Unrated severityNVD Advisory· Published Nov 12, 2019· Updated Aug 4, 2024

CVE-2019-1449

CVE-2019-1449

Description

A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially crafted file, which could lead to a standard user, any AppContainer sandbox, and Office LPAC Protected View to escalate privileges to SYSTEM.To exploit this bug, an attacker would have to run a specially crafted file, aka 'Microsoft Office ClickToRun Security Feature Bypass Vulnerability'.

Affected products

2
  • Range: 2019 for 32-bit editions
  • Microsoft/Office 365 ProPlusv5
    Range: 32-bit Systems

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.