peter bassill · operator
$ cve CVE-2019-1297 JSON

CVE-2019-1297 KEV

8.8
HIGH · CVSS 3.1 · EPSS 21.8% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2022-03-17.

Description

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS21.81% — more likely to be exploited than 98% of all CVEs
On CISA KEVyes — remediate by 2022-03-17
Public exploitnone known
Published2019-09-11
Last modified2026-06-17

CISA KEV

NameMicrosoft Excel Remote Code Execution Vulnerability
Added2022-03-03
Due2022-03-17
Vendor / productMicrosoft / Excel
Ransomware usenone reported

Affected (3)

VendorProduct
microsoftexcel
microsoftoffice
microsoftoffice 365 proplus

References

→ the Explorer  ·  watch your stack  ·  NVD