CVE-2019-0541
published 2019-01-08CVE-2019-0541: A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution…
PriorityP185high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
53.20%
98.9th percentile
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.
Affected
59 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel_viewer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer_10 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Look for HTML/XHTML documents containing a <meta> tag with name set to 'ProgId' and content set to 'HTAFILE' (or other ProgId values), which is the trigger mechanism for this exploit. ↗
- →Monitor for msohtmed.exe (MS Office HTML Edit app) spawning unexpected child processes, particularly when opening HTML or XHTML files from network shares, as this is a key exploitation vector. ↗
- →Alert on HTML editing attack scenarios where a user is tricked into editing a specially crafted file via MSHTML engine — monitor for Internet Explorer or Office components loading and editing externally-sourced HTML/XHTML files. ↗
- ·On patched systems (post-December 2018 patches), the PoC file will open in Notepad instead of executing the malicious ProgId, confirming the patch is effective. Unpatched systems running Windows 7 SP1, Server 2008, Server 2012, Server 2012 R2, 8.0, 8.1, and Windows 10 (any version fully patched only up to December 2018) on both x86 and x64 are vulnerable. ↗
- ·The exploit is similar in mechanism to historical Windows Shell/IE ClassId vulnerabilities; detection logic built for those (ProgId/ClassId abuse via meta tags) may be reusable here. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
vendor_msrc6.4MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft MSHTML Remote Code Execution Vulnerability
cisa·2021-11-03·CVSS 8.8
CVE-2019-0541 [HIGH] CWE-77 Microsoft MSHTML Remote Code Execution Vulnerability
Vulnerability: Microsoft MSHTML Remote Code Execution Vulnerability
Affected: Microsoft MSHTML
Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-0541
Remediation Due Date: 2022-05-03
Microsoft
MSHTML Engine Remote Code Execution Vulnerability
vendor_msrc·2019-01-08·CVSS 6.4
CVE-2019-0541 [HIGH] MSHTML Engine Remote Code Execution Vulnerability
MSHTML Engine Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input.
An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
In a HTML editing attack scenario, an attacker could trick a user into editing a specially crafted file that is designed to exploit the vulnerability.
The security update addresses the vulnerability by modifying how MSHTML engine validates input.
Internet Explorer: Int
GHSA
GHSA-f832-7fhg-m78h: A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vu
ghsa_unreviewed·2022-05-13
CVE-2019-0541 [HIGH] CWE-77 GHSA-f832-7fhg-m78h: A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vu
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.
VulnCheck
Microsoft MSHTML Remote Code Execution Vulnerability
vulncheck·2019·CVSS 8.8
CVE-2019-0541 [HIGH] CWE-77 Microsoft MSHTML Remote Code Execution Vulnerability
Microsoft MSHTML Remote Code Execution Vulnerability
Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability.
Affected: Microsoft MSHTML
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-05-03
No detection rules found.
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Trendmicro
January Patch Tuesday Contains Fixes for DHCP
blogs_trendmicro·2019-01-09·CVSS 9.8
[CRITICAL] January Patch Tuesday Contains Fixes for DHCP
Sfruttamento vulnerabilità
## January Patch Tuesday Contains Fixes for DHCP
Microsoft starts off 2019 relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
By: Trend Micro Research Jan 09, 2019 Read time: ( words)
Save to Folio
In the last few months of 2018, Microsoft’s regular security releases included patches for vulnerabilities that were actively being exploited . Thankfully, 2019 started off relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
The most notable
Trendmicro
January Patch Tuesday Contains Fixes for DHCP
blogs_trendmicro·2019-01-09·CVSS 9.8
[CRITICAL] January Patch Tuesday Contains Fixes for DHCP
Exploits & Vulnerabilities
## January Patch Tuesday Contains Fixes for DHCP
Microsoft starts off 2019 relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
By: Trend Micro Research Jan 09, 2019 Read time: ( words)
Save to Folio
In the last few months of 2018, Microsoft’s regular security releases included patches for vulnerabilities that were actively being exploited . Thankfully, 2019 started off relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
The most notable
Trendmicro
January Patch Tuesday Contains Fixes for DHCP
blogs_trendmicro·2019-01-09·CVSS 9.8
[CRITICAL] January Patch Tuesday Contains Fixes for DHCP
Ausnutzung von Schwachstellen
## January Patch Tuesday Contains Fixes for DHCP
Microsoft starts off 2019 relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
By: Trend Micro Research Jan 09, 2019 Read time: ( words)
Save to Folio
In the last few months of 2018, Microsoft’s regular security releases included patches for vulnerabilities that were actively being exploited . Thankfully, 2019 started off relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
The most notab
Trendmicro
January Patch Tuesday Contains Fixes for DHCP
blogs_trendmicro·2019-01-09·CVSS 9.8
[CRITICAL] January Patch Tuesday Contains Fixes for DHCP
Exploits & Vulnerabilities
## January Patch Tuesday Contains Fixes for DHCP
Microsoft starts off 2019 relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
By: Trend Micro Research 2019/01/09 Read time: ( words)
Save to Folio
In the last few months of 2018, Microsoft’s regular security releases included patches for vulnerabilities that were actively being exploited . Thankfully, 2019 started off relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
The most notable of
Trendmicro
January Patch Tuesday Contains Fixes for DHCP
blogs_trendmicro·2019-01-09·CVSS 9.8
[CRITICAL] January Patch Tuesday Contains Fixes for DHCP
Exploits y vulnerabilidades
## January Patch Tuesday Contains Fixes for DHCP
Microsoft starts off 2019 relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
By: Trend Micro Research Jan 09, 2019 Read time: ( words)
Save to Folio
In the last few months of 2018, Microsoft’s regular security releases included patches for vulnerabilities that were actively being exploited . Thankfully, 2019 started off relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
The most notable
Trendmicro
January Patch Tuesday Contains Fixes for DHCP
blogs_trendmicro·2019-01-09·CVSS 9.8
[CRITICAL] January Patch Tuesday Contains Fixes for DHCP
Exploits & Vulnerabilities
# January Patch Tuesday Contains Fixes for DHCP
Microsoft starts off 2019 relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
By: Trend Micro Research
Jan 09, 2019
Read time: ( words)
Save to Folio
In the last few months of 2018, Microsoft’s regular security releases included patches for vulnerabilities that were actively being exploited. Thankfully, 2019 started off relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
The most notable o
Trendmicro
January Patch Tuesday Contains Fixes for DHCP
blogs_trendmicro·2019-01-09·CVSS 9.8
[CRITICAL] January Patch Tuesday Contains Fixes for DHCP
Exploits & Vulnerabilities
# January Patch Tuesday Contains Fixes for DHCP
Microsoft starts off 2019 relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
By: Trend Micro Research
2019/01/09
Read time: ( words)
Save to Folio
In the last few months of 2018, Microsoft’s regular security releases included patches for vulnerabilities that were actively being exploited. Thankfully, 2019 started off relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
The most notable of
Zscaler
6 New Microsoft Security Vulnerabilities | Zscaler Advisory
blogs_zscaler·CVSS 7.5
[HIGH] 6 New Microsoft Security Vulnerabilities | Zscaler Advisory
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
http://www.securityfocus.com/bid/106402https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0541https://www.exploit-db.com/exploits/46536/http://www.securityfocus.com/bid/106402https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0541https://www.exploit-db.com/exploits/46536/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0541
2019-01-08
Published
2021-11-03
Added to CISA KEV
Exploited in the wild