Junglewise Threat Intelligence

CVE-2019-0541: Microsoft MSHTML Remote Code Execution Vulnerability

CVE-2019-0541 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Mshtml. Vendors: Microsoft.

Executive brief

A remote code execution vulnerability exists in the Microsoft MSHTML engine due to improper input validation. An attacker could exploit this by convincing a user to view specially crafted content, potentially leading to full system compromise.

Affected products

  • Microsoft MSHTML engine
  • Microsoft Internet Explorer 9
  • Microsoft Internet Explorer 10
  • Microsoft Internet Explorer 11
  • Microsoft Office 365 ProPlus
  • Microsoft Office Word Viewer
  • Microsoft Excel Viewer

Timeline

  • 2019-01-08: advisory: MSRC advisory published (based on CVE ID year and bid date)
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed

Related threats