Critical severity9.8NVD Advisory· Published Nov 12, 2019· Updated Jun 17, 2026
CVE-2019-1449
CVE-2019-1449
Description
A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially crafted file, which could lead to a standard user, any AppContainer sandbox, and Office LPAC Protected View to escalate privileges to SYSTEM.To exploit this bug, an attacker would have to run a specially crafted file, aka 'Microsoft Office ClickToRun Security Feature Bypass Vulnerability'.
Affected products
5cpe:2.3:a:microsoft:office_365_proplus:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microsoft:office_365_proplus:-:*:*:*:*:*:*:*
- (no CPE)range: 32-bit Systems
- Range: 2019 for 32-bit editions
Patches
Vulnerability mechanics
References
1- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1449nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.