Back

CVE-2019-1449

CRITICAL

A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially crafted file, which could lead to a standard user, any AppContainer sandbox, and Office LPAC Protected View to escalate privileges to SYSTEM.To exploit this bug, an attacker would have to run a specially crafted file, aka 'Microsoft Office ClickToRun Security Feature Bypass Vulnerability'.

Published: Nov 12, 2019 Modified: Jun 17, 2026
NVD-CWE-noinfo

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (2)

Vendor Product Version
microsoft office 2019
microsoft office_365_proplus -

GitHub Security Advisory GHSA-hgr7-mfwx-6c5g

A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R)...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 6.36%

Top 7% most likely to be exploited

Threat Score 41.1 / 100

Data Sources

NVD EPSS GitHub