CVE-2019-0561: Microsoft Office

Medium severity, CVSS 5.5. EPSS: 7.9% chance of exploitation in the next 30 days.

An information disclosure vulnerability exists when Microsoft Word macro buttons are used improperly, aka "Microsoft Word Information Disclosure Vulnerability." This affects Microsoft Word, Office 365 ProPlus, Microsoft Office, Word.

Affected products

  • Microsoft Office: version 2010 only; version 2016 only; version 2019 only
  • Microsoft Office 365 Proplus: affected versions not specified
  • Microsoft Office Web Apps Server: version 2010 only
  • Microsoft SharePoint Server: version 2010 only
  • Microsoft Word: version 2010 only; version 2013 only; version 2016 only
  • Microsoft Word Automation Services: affected versions not specified

Published 2019-01-08. Last modified 2026-06-17.