9.3

CVE-2019-0541

Warnung
Exploit
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version 11
   Microsoft ≫ Windows 10 1507 Version - HwPlatform x64
   Microsoft ≫ Windows 10 1507 Version - HwPlatform x86
   Microsoft ≫ Windows 10 1607 Version - HwPlatform x64
   Microsoft ≫ Windows 10 1607 Version - HwPlatform x86
   Microsoft ≫ Windows 10 1703 Version - HwPlatform x64
   Microsoft ≫ Windows 10 1703 Version - HwPlatform x86
   Microsoft ≫ Windows 10 1709 Version - HwPlatform arm64
   Microsoft ≫ Windows 10 1709 Version - HwPlatform x64
   Microsoft ≫ Windows 10 1709 Version - HwPlatform x86
   Microsoft ≫ Windows 10 1803 Version - HwPlatform arm64
   Microsoft ≫ Windows 10 1803 Version - HwPlatform x64
   Microsoft ≫ Windows 10 1803 Version - HwPlatform x86
   Microsoft ≫ Windows 10 1809 Version - HwPlatform arm64
   Microsoft ≫ Windows 10 1809 Version - HwPlatform x64
   Microsoft ≫ Windows 10 1809 Version - HwPlatform x86
   Microsoft ≫ Windows 7 Version - Update sp1
   Microsoft ≫ Windows 8.1 Version -
   Microsoft ≫ Windows Rt 8.1 Version -
   Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform x64
   Microsoft ≫ Windows Server 2012 Version r2
   Microsoft ≫ Windows Server 2016 Version -
   Microsoft ≫ Windows Server 2019 Version -
Microsoft ≫ Excel Viewer Version 2007 Update sp3
Microsoft ≫ Office Version 2010 Update sp2
Microsoft ≫ Office Version 2013 Update sp1
Microsoft ≫ Office Version 2013 Update sp1 SwEdition rt
Microsoft ≫ Office Version 2016
Microsoft ≫ Office Version 2019
Microsoft ≫ Internet Explorer Version 9
   Microsoft ≫ Windows Server 2008 Version - Update sp2
Microsoft ≫ Internet Explorer Version 10
   Microsoft ≫ Windows Server 2012 Version -

03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft MSHTML Remote Code Execution Vulnerability

Schwachstelle

Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 53.2% 0.988
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

http://www.securityfocus.com/bid/106402
Third Party Advisory
Broken Link
VDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0541
Patch
Vendor Advisory
https://www.exploit-db.com/exploits/46536/
Third Party Advisory
Exploit
VDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0541
US Government Resource