cbcvebase.
CVE-2019-0541
published 2019-01-08

CVE-2019-0541: A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution…

PriorityP185high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
53.20%
98.9th percentile
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.

Affected

59 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftexcel_viewer
microsoftinternet_explorer
microsoftinternet_explorer
microsoftinternet_explorer
microsoftinternet_explorer_10
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11

Detection & IOCsextracted from sources · hover to see the quote

filenamemsohtmed.exe
  • Look for HTML/XHTML documents containing a <meta> tag with name set to 'ProgId' and content set to 'HTAFILE' (or other ProgId values), which is the trigger mechanism for this exploit.
  • Monitor for msohtmed.exe (MS Office HTML Edit app) spawning unexpected child processes, particularly when opening HTML or XHTML files from network shares, as this is a key exploitation vector.
  • Alert on HTML editing attack scenarios where a user is tricked into editing a specially crafted file via MSHTML engine — monitor for Internet Explorer or Office components loading and editing externally-sourced HTML/XHTML files.
  • ·On patched systems (post-December 2018 patches), the PoC file will open in Notepad instead of executing the malicious ProgId, confirming the patch is effective. Unpatched systems running Windows 7 SP1, Server 2008, Server 2012, Server 2012 R2, 8.0, 8.1, and Windows 10 (any version fully patched only up to December 2018) on both x86 and x64 are vulnerable.
  • ·The exploit is similar in mechanism to historical Windows Shell/IE ClassId vulnerabilities; detection logic built for those (ProgId/ClassId abuse via meta tags) may be reusable here.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
vendor_msrc6.4MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.