CVE-2019-0541
Microsoft MSHTML Remote Code Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 53.20% probability · 99th percentile
- CISA KEV
- Listed 3 November 2021 · due 3 May 2022
- Weakness
- CWE-77
- Affected
- microsoft/internet explorer · microsoft/excel viewer · microsoft/office · microsoft/office 365 proplus · microsoft/office word viewer
- Source
- secure@microsoft.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-0541
References
- http://www.securityfocus.com/bid/106402Broken Link, Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0541Patch, Vendor Advisory
- https://www.exploit-db.com/exploits/46536/Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/106402Broken Link, Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0541Patch, Vendor Advisory
- https://www.exploit-db.com/exploits/46536/Exploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0541US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.