Important EPSS 0.06363 2019-11 archive

Executive Summary

A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially crafted file, which could lead to a standard user, any AppContainer sandbox, and Office LPAC Protected View to escalate privileges to SYSTEM. To exploit this bug, an attacker would have to run a specially crafted file. The security update addresses how C2R components handle these files.

Overview

Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Security Feature Bypass
Released Nov 12 2019
Last Updated Nov 12 2019
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.06363 — 0.92761 percentile

EPSS Score

0.06363
probability of exploitation in the next 30 days
0.92761 percentile - updated 2026-06-20
View on FIRST.org

Affected Products

4 affected products
Product KB Article Severity Impact Restart Required
Microsoft Office 2019 for 32-bit editions Click to Run (Security Update) Important Security Feature Bypass No
Microsoft Office 2019 for 64-bit editions Click to Run (Security Update) Important Security Feature Bypass No
Office 365 ProPlus for 32-bit Systems Click to Run (Security Update) Important Security Feature Bypass No
Office 365 ProPlus for 64-bit Systems Click to Run (Security Update) Important Security Feature Bypass No

Patches

1 patch
Article Type Restart
Click to Run Security Update No

Known Exploits

Acknowledgments

Ben Faull of Microsoft Corporation