EXPOSURES › CVE-2019-1297
CVE-2019-1297
HIGH ⌖ ON CISA KEV · EXPLOITEDMicrosoft Excel contained an unpatched remote code execution vulnerability that was actively exploited in the wild.
Microsoft Excel failed to properly handle objects in memory, allowing remote code execution. DIB organizations must ensure all Microsoft products are patched promptly, as unpatched RCE vulnerabilities are frequently exploited by threat actors to compromise systems and exfiltrate data.
Shame score — A known RCE vulnerability in a widely used productivity tool remained unpatched and was actively exploited in the wild, demonstrating a failure in timely patch management and leaving systems exposed to remote attackers.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |