ZeroHour

CVE-2019-1297

KEVmass

Remote Code Execution via Memory Corruption in Microsoft Excel

CISA: Microsoft Excel Remote Code Execution Vulnerability

CVSS 3.1
8.8 high
EPSS
22%p98
Published
()
KEV added
AI analysis

CVE-2019-1297 is a remote code execution vulnerability in Microsoft Excel caused by the software failing to properly handle objects in memory. An attacker triggers it by persuading a user to open a specially crafted spreadsheet, for example an emailed attachment or a file downloaded from a malicious link, so user interaction is required. Successful exploitation lets the attacker execute arbitrary code in the context of the current user, gaining the privileges of that account rather than automatic system-level access. Anyone running an affected version of Excel at the time of disclosure is affected, with organizational risk concentrated on endpoints where users open untrusted spreadsheets. The flaw is known to be exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, and EPSS assigns a roughly 22% probability of exploitation within 30 days (97th percentile), while no public proof-of-concept or confirmed ransomware linkage is documented.

What to do: Apply Microsoft's security updates for Excel/Office (2019 Patch Tuesday cycle or any later cumulative Office update) via Microsoft Update and verify installed Office build numbers against the Microsoft advisory. Until patched, train users not to open spreadsheets from untrusted sources and rely on Office Protected View for internet-sourced files, and hunt endpoints for exploitation indicators given the KEV listing.

Affected
Microsoft Excel
Estimated exposure
masshundreds of millions of Office/Excel users worldwide (Excel ships with Microsoft Office and Microsoft 365); actual exposure limited to unpatched builds — Excel is a core component of Microsoft Office and Microsoft 365, which have hundreds of millions of users globally, so the install base is enormous but the vulnerable population is bounded by how many endpoints remain unpatched.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.

CISA Known Exploited Vulnerability
Affected
Microsoft Excel
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
excel, office, office 365 proplus
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.