Site icon API Security Blog

Security Updates for Microsoft Project C2R (September 2019)

The Microsoft Project installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability :

– A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could execute arbitrary commands. In a file-sharing attack scenario, an attacker could provide a specially crafted document file designed to exploit the vulnerability, and then convince a user to open the document file and interact with the document by clicking a specific cell.
The update addresses the vulnerability by correcting how Microsoft Office handles input. (CVE-2019-1264)Read More

Exit mobile version