CVE-2019-0559: Microsoft Office

Medium severity, CVSS 6.5. EPSS: 6.8% chance of exploitation in the next 30 days.

An information disclosure vulnerability exists when Microsoft Outlook improperly handles certain types of messages, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook.

Affected products

  • Microsoft Office: version 2019 only
  • Microsoft Office 365 Proplus: affected versions not specified
  • Microsoft Outlook: version 2010 only; version 2013 only; version 2016 only

Published 2019-01-08. Last modified 2026-06-17.