CVE-2019-0541
high · 8.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2021-11-03Remediation due 2022-05-03
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.
8.8
CVSS
53.2%
EPSS (exploit prob.)
99th
EPSS percentile
2019-01-08
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-77
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | internet_explorer | 11 |
| microsoft | windows_10_1507 | all versions |
| microsoft | windows_10_1507 | all versions |
| microsoft | windows_10_1607 | all versions |
| microsoft | windows_10_1607 | all versions |
| microsoft | windows_10_1703 | all versions |
| microsoft | windows_10_1703 | all versions |
| microsoft | windows_10_1709 | all versions |
| microsoft | windows_10_1709 | all versions |
| microsoft | windows_10_1709 | all versions |
| microsoft | windows_10_1803 | all versions |
| microsoft | windows_10_1803 | all versions |
| microsoft | windows_10_1803 | all versions |
| microsoft | windows_10_1809 | all versions |
| microsoft | windows_10_1809 | all versions |
| microsoft | windows_10_1809 | all versions |
| microsoft | windows_7 | all versions |
| microsoft | windows_8.1 | all versions |
| microsoft | windows_rt_8.1 | all versions |
| microsoft | windows_server_2008 | r2 |
| microsoft | windows_server_2012 | r2 |
| microsoft | windows_server_2016 | all versions |
| microsoft | windows_server_2019 | all versions |
| microsoft | excel_viewer | 2007 |
| microsoft | office | 2010 |
| microsoft | office | 2013 |
| microsoft | office | 2013 |
| microsoft | office | 2016 |
| microsoft | office | 2019 |
| microsoft | office_365_proplus | all versions |
| microsoft | office_word_viewer | all versions |
| microsoft | internet_explorer | 9 |
| microsoft | windows_server_2008 | all versions |
| microsoft | internet_explorer | 10 |
| microsoft | windows_server_2012 | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/106402
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0541
- https://www.exploit-db.com/exploits/46536/
- http://www.securityfocus.com/bid/106402
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0541
- https://www.exploit-db.com/exploits/46536/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0541
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-0541