CVE-2019-0540: Microsoft Excel Viewer

Medium severity, CVSS 5.5. EPSS: 12.8% chance of exploitation in the next 30 days.

A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'.

Affected products

  • Microsoft Excel Viewer: affected versions not specified
  • Microsoft Office: version 2010 only; version 2013 only; version 2016 only; version 2019 only
  • Microsoft Office 365 Proplus: affected versions not specified
  • Microsoft PowerPoint Viewer: affected versions not specified
  • Microsoft Word Viewer: affected versions not specified

Published 2019-03-05. Last modified 2026-06-17.