CVE-2019-1445: vulnerability in Microsoft Office Online Server
Published · Updated
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.8%
exploitation probability
0.8%top 45% of all CVEs
observed exploitation
nono source reports it
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1447.
Affected products
Microsoft · Office Online ServerRelated CVEs — Microsoft Office Online Server
In the same product, most dangerous first.
CVE-2019-1331—CVE-2019-1331EPSS 19.7%CVE-2018-8628—CVE-2018-8628EPSS 15.9%CVE-2021-31939HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 13.3%CVE-2020-1495—Microsoft Excel Remote Code Execution VulnerabilityEPSS 4.2%CVE-2020-17123HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 3.6%CVE-2021-24069HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 2.5%