CVE-2019-1236
published 2019-09-11CVE-2019-1236: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'…
PriorityP346high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
7.75%
94.0th percentile
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1208.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer_10 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vendor_msrc6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v9rw-w6gg-x642: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulner
ghsa_unreviewed·2022-05-24·CVSS 7.5
CVE-2019-1208 [HIGH] GHSA-v9rw-w6gg-x642: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulner
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1236.
GHSA
GHSA-rh9m-8vch-h2gr: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulner
ghsa_unreviewed·2022-05-24·CVSS 7.5
CVE-2019-1236 [HIGH] GHSA-rh9m-8vch-h2gr: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulner
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1208.
GHSA
Alkacon OpenCMS CSV Injection via New User module
ghsa·2022-05-24
CVE-2019-11819 [HIGH] CWE-1236 Alkacon OpenCMS CSV Injection via New User module
Alkacon OpenCMS CSV Injection via New User module
Alkacon OpenCMS v10.5.4 and before is affected by CSV (aka Excel Macro) Injection in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp) via the First Name or Last Name.
Microsoft
VBScript Remote Code Execution Vulnerability
vendor_msrc·2019-09-10·CVSS 6.4
CVE-2019-1236 [HIGH] VBScript Remote Code Execution Vulnerability
VBScript Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exp
No detection rules found.
No public exploits indexed.
Trendmicro
September Patch Tuesday: RDP Vulns and Zero-Days
blogs_trendmicro·2019-09-11·CVSS 8.8
[HIGH] September Patch Tuesday: RDP Vulns and Zero-Days
Exploits & Vulnerabilities
# September Patch Tuesday: RDP Vulns and Zero-Days
Microsoft’s September Patch Tuesday covered a total of 80 CVEs, 17 of which were rated critical.
By: Trend Micro
2019/09/11
Read time: ( words)
Save to Folio
Microsoft’s September Patch Tuesday covered 80 CVEs, 17 of which were rated critical, and included patches for Azure DevOps Server, Chakra Scripting engine, and Microsoft SharePoint. Sixty-two were labeled as important and included patches for Microsoft Excel, Microsoft Edge, and Microsoft Exchange. Only one was rated as moderate.
### Remote desktop vulnerabilities
Continuing the trend from last month, several of the critical patches were for Remote Desktop Clients and are CVE-2019-0787, CVE-2019-0788, CVE-2019-1290, and CVE-2019-1291 — all Remote Co
Trendmicro
September Patch Tuesday: RDP Vulns and Zero-Days
blogs_trendmicro·2019-09-11·CVSS 8.8
[HIGH] September Patch Tuesday: RDP Vulns and Zero-Days
# September Patch Tuesday: RDP Vulns and Zero-Days
Microsoft’s September Patch Tuesday covered a total of 80 CVEs, 17 of which were rated critical.
By: Trend Micro
Sep 11, 2019
Read time: ( words)
Save to Folio
Microsoft’s September Patch Tuesday covered 80 CVEs, 17 of which were rated critical, and included patches for Azure DevOps Server, Chakra Scripting engine, and Microsoft SharePoint. Sixty-two were labeled as important and included patches for Microsoft Excel, Microsoft Edge, and Microsoft Exchange. Only one was rated as moderate.
### Remote desktop vulnerabilities
Continuing the trend from last month, several of the critical patches were for Remote Desktop Clients and are CVE-2019-0787, CVE-2019-0788, CVE-2019-1290, and CVE-2019-1291 — all Remote Code Execution (RCE) vulnera
Bugzilla
CVE-2019-0820 dotnet: timeouts for regular expressions are not enforced
bugzilla·2019-05-02·CVSS 7.5
CVE-2019-0820 [HIGH] CVE-2019-0820 dotnet: timeouts for regular expressions are not enforced
CVE-2019-0820 dotnet: timeouts for regular expressions are not enforced
It was discovered that RegEx strings were not properly processed, which can be exploited by anauthenticated remote attackers to cause a Denial of Service by sending specially crafted requests to a .NET Core application.
External references:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0820
Discussion:
This issue has been addressed in the following products:
.NET Core on Red Hat Enterprise Linux
Via RHSA-2019:1236 https://access.redhat.com/errata/RHSA-2019:1236
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:1259 https://access.redhat.com/errata/RHSA-2019:1259
Bugzilla
CVE-2019-0980 dotnet: infinite loop in Uri.TryCreate leading to ASP.Net Core Denial of Service
bugzilla·2019-05-02·CVSS 7.5
CVE-2019-0980 [HIGH] CVE-2019-0980 dotnet: infinite loop in Uri.TryCreate leading to ASP.Net Core Denial of Service
CVE-2019-0980 dotnet: infinite loop in Uri.TryCreate leading to ASP.Net Core Denial of Service
An infinite loop flaw related to URI.TryCreate when processing certain web requests can be exploited by unauthenticated remote attackers to cause a Denial of Service by sending specially crafted requests to a .NET Core application.
External references:
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2019-0980
Discussion:
This issue has been addressed in the following products:
.NET Core on Red Hat Enterprise Linux
Via RHSA-2019:1236 https://access.redhat.com/errata/RHSA-2019:1236
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:1259 https://access.redhat.com/errata/RHSA-2019:1259
Bugzilla
CVE-2019-0981 dotnet: crash in IPAddress.TryCreate leading to ASP.Net Core Denial of Service
bugzilla·2019-05-02·CVSS 7.5
CVE-2019-0981 [HIGH] CVE-2019-0981 dotnet: crash in IPAddress.TryCreate leading to ASP.Net Core Denial of Service
CVE-2019-0981 dotnet: crash in IPAddress.TryCreate leading to ASP.Net Core Denial of Service
An error related to IPAddress.TryCreate when processing certain web requests can be exploited by unauthenticated remote attackers to cause a Denial of Service by sending specially crafted requests to a .NET Core application.
External references:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981
Discussion:
This issue has been addressed in the following products:
.NET Core on Red Hat Enterprise Linux
Via RHSA-2019:1236 https://access.redhat.com/errata/RHSA-2019:1236
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:1259 https://access.redhat.com/errata/RHSA-2019:1259
2019-09-11
Published