CVE-2019-1111
published 2019-07-15CVE-2019-1111: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel…
PriorityP354high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
13.16%
95.9th percentile
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1110.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | microsoft_excel | — | — |
| microsoft | microsoft_excel | — | — |
| microsoft | microsoft_excel | — | — |
| microsoft | microsoft_excel | — | — |
| microsoft | microsoft_excel | — | — |
| microsoft | microsoft_excel | — | — |
| microsoft | microsoft_excel | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Excel Remote Code Execution Vulnerability
vendor_msrc·2019-07-09·CVSS 8.8
CVE-2019-1111 [HIGH] Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Exploitation of the vulnerability requires that a user open a specially crafted file wit
GHSA
GHSA-p5cr-pxw6-w5h7: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2019-1110 [HIGH] GHSA-p5cr-pxw6-w5h7: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1111.
GHSA
GHSA-vpv6-p65m-8q25: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2019-1111 [HIGH] GHSA-vpv6-p65m-8q25: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1110.
Suricata
ET EXPLOIT DynoRoot DHCP - Client Command Injection
suricata·2018-06-29
CVE-2018-1111 ET EXPLOIT DynoRoot DHCP - Client Command Injection
ET EXPLOIT DynoRoot DHCP - Client Command Injection
Rule: alert udp any 67 -> any 68 (msg:"ET EXPLOIT DynoRoot DHCP - Client Command Injection"; content:"|02|"; depth:1; content:"|35 01 05 fc|"; distance:0; content:"|2f|bin|2f|sh"; fast_pattern; distance:0; reference:url,exploit-db.com/exploits/44652/; reference:cve,2018-1111; classtype:attempted-admin; sid:2025765; rev:2; metadata:attack_target Networking_Equipment, created_at 2018_06_29, cve CVE_2018_1111, deployment Datacenter, performance_impact Low, confidence Medium, signature_severity Critical, updated_at 2019_07_26, reviewed_at 2024_04_03, mitre_tactic_id TA0008, mitre_tactic_name Lateral_Movement, mitre_technique_id T1210, mitre_technique_name Exploitation_Of_Remote_Services;)
No public exploits indexed.
Bugzilla
CVE-2019-11373 mediainfo: out-of-bounds read in function File__Analyze::Get_L8 in File__Analyze_Buffer.cpp
bugzilla·2019-04-22·CVSS 6.5
CVE-2019-11373 [MEDIUM] CVE-2019-11373 mediainfo: out-of-bounds read in function File__Analyze::Get_L8 in File__Analyze_Buffer.cpp
CVE-2019-11373 mediainfo: out-of-bounds read in function File__Analyze::Get_L8 in File__Analyze_Buffer.cpp
An out-of-bounds read in File__Analyze::Get_L8 in File__Analyze_Buffer.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
Reference:
https://github.com/MediaArea/MediaInfoLib/pull/1111
https://sourceforge.net/p/mediainfo/bugs/1101/
Discussion:
Created libmediainfo tracking bugs for this issue:
Affects: fedora-all [bug 1701847]
Created mediainfo tracking bugs for this issue:
Affects: fedora-all [bug 1701845]
---
Created libmediainfo tracking bugs for this issue:
Affects: epel-all [bug 1701849]
Created mediainfo tracking bugs for this issue:
Affects: epel-all [bug 1701848]
Bugzilla
CVE-2019-11372 mediainfo: out-of-bounds read in function MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp
bugzilla·2019-04-22·CVSS 6.5
CVE-2019-11372 [MEDIUM] CVE-2019-11372 mediainfo: out-of-bounds read in function MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp
CVE-2019-11372 mediainfo: out-of-bounds read in function MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp
An out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
References:
https://github.com/MediaArea/MediaInfoLib/pull/1111
https://sourceforge.net/p/mediainfo/bugs/1101/
Discussion:
Created libmediainfo tracking bugs for this issue:
Affects: fedora-all [bug 1701847]
Created mediainfo tracking bugs for this issue:
Affects: fedora-all [bug 1701845]
---
Created libmediainfo tracking bugs for this issue:
Affects: epel-all [bug 1701849]
Created mediainfo tracking bugs for this issue:
Affects: epel-all [bug 1701848]
---
Should I apply https://patch-diff.githubus
2019-07-15
Published