CVE-2019-0790XML External Entity (XXE) Injection in Microsoft Windows

Severity
8.8HIGHNVD
EPSS
25.8%
top 3.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 9
Latest updateMay 14

Description

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0791, CVE-2019-0792, CVE-2019-0793, CVE-2019-0795.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages18 packages

CVEListV5microsoft/windows20 versions+19
NVDmicrosoft/windowsr2, 1709, 1803+2
NVDmicrosoft/windows_105 versions+4
CVEListV5microsoft/windows_server18 versions+17

Patches

🔴Vulnerability Details

5
GHSA
GHSA-f3xr-8j4w-q59x: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution2022-05-14
GHSA
GHSA-3g93-9f89-prgj: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution2022-05-14
GHSA
GHSA-8px2-qhm8-m3pc: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution2022-05-14
GHSA
GHSA-24rg-9rhw-m9gh: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution2022-05-14
GHSA
GHSA-w6p8-6mfr-rc8p: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution2022-05-14

📋Vendor Advisories

1
Microsoft
MS XML Remote Code Execution Vulnerability2019-04-09