Vulnerability Name: CVE-2019-0541 (CCN-154897) Assigned: 2018-11-26 Published: 2019-01-08 Updated: 2020-09-28 Summary: A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus. CVSS v3 Severity: 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H )7.9 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): RequiredScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
6.4 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H )5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): HighPrivileges Required (PR): HighUser Interaction (UI): RequiredScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
CVSS v2 Severity: 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:M/C:C/I:C/A:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): HighAthentication (Au): Multiple_InstancesImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
Vulnerability Type: CWE-77 Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2019-0541 Source: BID Type: Third Party Advisory, VDB Entry106402 Source: XF Type: UNKNOWNms-ie-cve20190541-code-exec(154897) Source: CCN Type: Packet Storm Security [03-13-2019]Microsoft Windows MSHTML Engine Edit Remote Code Execution Source: CCN Type: Microsoft Security TechCenter - January 2019Microsoft Internet Explorer Remote Code Vulnerability Source: CONFIRM Type: Patch, Vendor Advisoryhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0541 Source: CCN Type: CYBERSECURITY & INFRASTRUCTURE SECURITY AGENCYKNOWN EXPLOITED VULNERABILITIES CATALOG Source: EXPLOIT-DB Type: EXPLOITOffensive Security Exploit Database [03-13-2019] Source: EXPLOIT-DB Type: Exploit, Third Party Advisory, VDB Entry46536 Vulnerable Configuration: Configuration 1 :cpe:/a:microsoft:internet_explorer:11:*:*:*:*:*:*:* AND cpe:/o:microsoft:windows_10:-:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_10:1607:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_10:1703:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_10:1709:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_10:1803:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_10:1809:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_7:-:sp1:*:*:*:*:*:* OR cpe:/o:microsoft:windows_8.1:-:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2016:-:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2019:-:*:*:*:*:*:*:* Configuration 2 :cpe:/a:microsoft:excel_viewer:2007:sp3:*:*:*:*:*:* OR cpe:/a:microsoft:office:2010:sp2:*:*:*:*:*:* OR cpe:/a:microsoft:office:2013:sp1:*:*:*:*:*:* OR cpe:/a:microsoft:office:2013:sp1:*:*:rt:*:*:* OR cpe:/a:microsoft:office:2016:*:*:*:*:*:*:* OR cpe:/a:microsoft:office:2019:*:*:*:*:*:*:* OR cpe:/a:microsoft:office_365_proplus:-:*:*:*:*:*:*:* OR cpe:/a:microsoft:office_word_viewer:-:*:*:*:*:*:*:* Configuration 3 :cpe:/a:microsoft:internet_explorer:9:*:*:*:*:*:*:* AND cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:* Configuration 4 :cpe:/a:microsoft:internet_explorer:10:*:*:*:*:*:*:* AND cpe:/o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:microsoft:excel_viewer:-:*:*:*:*:*:*:* OR cpe:/a:microsoft:word_viewer:-:*:*:*:*:*:*:* OR cpe:/a:microsoft:internet_explorer:9:-:*:*:*:*:*:* OR cpe:/a:microsoft:internet_explorer:10:-:*:*:*:*:*:* OR cpe:/a:microsoft:office:2010:sp2:x64:*:*:*:*:* OR cpe:/a:microsoft:office:2010:sp2:x32:*:*:*:*:* OR cpe:/a:microsoft:internet_explorer:11:-:*:*:*:*:*:* OR cpe:/a:microsoft:office:2013:sp1:x32:*:*:*:*:* OR cpe:/a:microsoft:office:2013:sp1:*:*:*:*:x64:* OR cpe:/a:microsoft:office:2013:sp1:*:*:rt:*:*:* OR cpe:/a:microsoft:office:2016:*:x32:*:*:*:*:* OR cpe:/a:microsoft:office:2016:*:*:*:*:*:x64:* OR cpe:/a:microsoft:office:2019:*:~~~click-to-run~~:*:*:*:x32:* OR cpe:/a:microsoft:office:2019:*:*:*:click-to-run:*:x64:* OR cpe:/a:microsoft:office_365_proplus:-:*:*:*:*:*:x32:* OR cpe:/a:microsoft:office_365:-:*:*:*:proplus:*:x64:* AND cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x32:* OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x64:* OR cpe:/o:microsoft:windows_7:-:sp1:*:*:ultimate_n:*:x86:* OR cpe:/o:microsoft:windows_7::sp1:x64:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:* OR cpe:/o:microsoft:windows_server_2012:*:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_8.1:-:-:-:*:-:-:x32:* OR cpe:/o:microsoft:windows_8.1:::~~~~x64~:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_10:-:*:*:*:*:*:x32:* OR cpe:/o:microsoft:windows_10:::~~~~x64~:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2016:*:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2019:*:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_10:-:*:*:*:*:*:arm64:* Denotes that component is vulnerable BACK
microsoft internet explorer 11
microsoft windows 10 -
microsoft windows 10 1607
microsoft windows 10 1703
microsoft windows 10 1709
microsoft windows 10 1803
microsoft windows 10 1809
microsoft windows 7 - sp1
microsoft windows 8.1 -
microsoft windows rt 8.1 -
microsoft windows server 2012 r2
microsoft windows server 2016 -
microsoft windows server 2019 -
microsoft excel viewer 2007 sp3
microsoft office 2010 sp2
microsoft office 2013 sp1
microsoft office 2013 sp1
microsoft office 2016
microsoft office 2019
microsoft office 365 proplus -
microsoft office word viewer -
microsoft internet explorer 9
microsoft windows server 2008 - sp2
microsoft internet explorer 10
microsoft windows server 2012 -
microsoft excel viewer -
microsoft word viewer -
microsoft internet explorer 9 -
microsoft internet explorer 10 -
microsoft office 2010 sp2
microsoft office 2010 sp2
microsoft internet explorer 11 -
microsoft office 2013 sp1
microsoft office 2013 sp1
microsoft office 2013 sp1
microsoft office 2016
microsoft office 2016
microsoft office 2019
microsoft office 2019
microsoft office 365 proplus -
microsoft office 365 -
microsoft windows server 2008 sp2
microsoft windows server 2008 sp2
microsoft windows 7 - sp1
microsoft windows 7 sp1
microsoft windows server 2008 r2
microsoft windows server 2012
microsoft windows 8.1 - -
microsoft windows 8.1
microsoft windows server 2012 r2
microsoft windows rt 8.1 -
microsoft windows 10 -
microsoft windows 10
microsoft windows server 2016
microsoft windows server 2019
microsoft windows 10 -