CVE-2019-1400
Last modified
CVE-2019-1400 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory, aka 'Microsoft Access Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1463.. EPSS estimates a 2.16% chance of exploitation in the next 30 days.
Description
An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory, aka 'Microsoft Access Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1463.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Office | 2010 | Sp2 |
| Microsoft | Office | 2013 | Sp1 |
| Microsoft | Office | 2016 | — |
| Microsoft | Office | 2019 | — |
| Microsoft | Office 365 Proplus | All versions | — |
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1400Patch, Vendor Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1400Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-1400?
How severe is CVE-2019-1400?
How do I fix CVE-2019-1400?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-13994u'Lack of check that the current received data fragment size…7.8
- CVE-2019-13995u'Lack of integer overflow check for addition of fragment si…7.8
- CVE-2019-13996Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-13997Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-13998u'Lack of check that the TX FIFO write and read indices that…7.8
- CVE-2019-13999u'Lack of check for integer overflow for round up and additi…7.8
- CVE-2019-14000Lack of check that the RX FIFO write index that is read from…7.8
- CVE-2019-14001Wrong public key usage from existing oem_keystore for hash g…7.8
- CVE-2019-14002APKs without proper permission may bind to CallEnhancementSe…7.8
- CVE-2019-14003Null pointer exception can happen while parsing invalid MKV …7.5
- CVE-2019-14004Buffer overflow occurs while processing invalid MKV clip, wh…9.8
- CVE-2019-14005Buffer overflow occur while playing the clip which is nonsta…9.8
Are you affected by CVE-2019-1400?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
