CVE-2019-0541
KEV PoC massRemote Code Execution in Microsoft MSHTML Engine (Office and Internet Explorer)
CISA: Microsoft MSHTML Remote Code Execution Vulnerability
CVE-2019-0541 is a remote code execution vulnerability caused by improper input validation in Microsoft's MSHTML engine, the component that renders HTML content inside Internet Explorer and embedded objects in Office documents. It is triggered when a user opens attacker-crafted content, such as a malicious web page viewed in Internet Explorer or a specially crafted Office document, and requires no privileges but does require user interaction (CVSS 3.1 vector AV:N/AC:L/PR:N/UI:R). A successful attacker gains arbitrary code execution in the context of the current user, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score of 8.8). Affected products include Internet Explorer 9, 10, and 11, Microsoft Office including Office 365 ProPlus, and the legacy Office Word Viewer and Excel Viewer, meaning virtually any Windows environment using these components is exposed. The flaw has been exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 and a public proof of concept exists — EPSS estimates a 53.2% probability of exploitation within 30 days (99th percentile), and it was fixed in Microsoft's January 2019 Patch Tuesday updates.
What to do: Apply Microsoft's January 2019 Patch Tuesday security updates immediately across all Windows, Internet Explorer, and Office installations (including Office 365 ProPlus), prioritizing endpoints required by CISA KEV's stated action to apply updates per vendor instructions. Remove or replace the end-of-life Office Word Viewer and Excel Viewer, and reduce reliance on Internet Explorer while warning users not to open untrusted documents or links, since user interaction is required for exploitation. Hunt for signs of compromise on unpatched systems, as the KEV listing confirms in-the-wild exploitation (ransomware use: unknown).
| Microsoft Internet Explorer | 9, 10, and 11 |
| Microsoft Office | — |
| Microsoft Office 365 ProPlus | — |
| Microsoft Office Word Viewer | — |
| Microsoft Excel Viewer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.
- Affected
- Microsoft MSHTML
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- internet explorer, excel viewer, office, office 365 proplus, office word viewer
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H