CVE-2019-0540: Microsoft Excel Viewer
Medium severity, CVSS 5.5. EPSS: 12.8% chance of exploitation in the next 30 days.
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'.
Affected products
- Microsoft Excel Viewer: affected versions not specified
- Microsoft Office: version 2010 only; version 2013 only; version 2016 only; version 2019 only
- Microsoft Office 365 Proplus: affected versions not specified
- Microsoft PowerPoint Viewer: affected versions not specified
- Microsoft Word Viewer: affected versions not specified
Published 2019-03-05. Last modified 2026-06-17.