A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially crafted file, which could lead to a standard user, any AppContainer sandbox, and Office LPAC Protected View to escalate privileges to SYSTEM.To exploit this bug, an attacker would have to run a specially crafted file, aka 'Microsoft Office ClickToRun Security Feature Bypass Vulnerability'.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-10006 A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially crafted file, which could lead to a standard user, any AppContainer sandbox, and Office LPAC Protected View to escalate privileges to SYSTEM.To exploit this bug, an attacker would have to run a specially crafted file, aka 'Microsoft Office ClickToRun Security Feature Bypass Vulnerability'.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2024-08-04T18:20:27.673Z

Reserved: 2018-11-26T00:00:00

Link: CVE-2019-1449

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-11-12T19:15:16.020

Modified: 2024-11-21T04:36:43.243

Link: CVE-2019-1449

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses