CVE-2019-0541

HIGH

Description

A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.

References

http://www.securityfocus.com/bid/106402

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0541

https://www.exploit-db.com/exploits/46536/

Details

Source: MITRE

Published: 2019-01-08

Updated: 2020-09-28

Type: CWE-77

Risk Information

CVSS v2.0

Base Score: 9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 8.6

Severity: HIGH

CVSS v3.0

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 2.8

Severity: HIGH

Tenable Plugins

View all (11 total)

IDNameProductFamilySeverity
121025Security Updates for Microsoft Office Viewer Products (January 2019)NessusWindows : Microsoft Bulletins
high
121024Security Updates for Microsoft Office Products (January 2019)NessusWindows : Microsoft Bulletins
high
121023Security Updates for Internet Explorer (January 2019)NessusWindows : Microsoft Bulletins
high
121019KB4480972: Windows Server 2012 January 2019 Security UpdateNessusWindows : Microsoft Bulletins
high
121018KB4480973: Windows 10 Version 1703 January 2019 Security UpdateNessusWindows : Microsoft Bulletins
high
121017KB4480960: Windows 7 and Windows Server 2008 R2 January 2019 Security UpdateNessusWindows : Microsoft Bulletins
high
121016KB4480957: Windows Server 2008 January 2019 Security UpdateNessusWindows : Microsoft Bulletins
high
121014KB4480964: Windows 8.1 and Windows Server 2012 R2 January 2019 Security UpdateNessusWindows : Microsoft Bulletins
high
121013KB4480962: Windows 10 January 2019 Security UpdateNessusWindows : Microsoft Bulletins
high
121012KB4480961: Windows 10 Version 1607 and Windows Server 2016 January 2019 Security UpdateNessusWindows : Microsoft Bulletins
high
121011KB4480116: Windows 10 Version 1809 and Windows Server 2019 January 2019 Security UpdateNessusWindows : Microsoft Bulletins
high