ZeroHour

CVE-2019-0541

KEV PoC mass

Remote Code Execution in Microsoft MSHTML Engine (Office and Internet Explorer)

CISA: Microsoft MSHTML Remote Code Execution Vulnerability

CVSS 3.1
8.8 high
EPSS
53%p99
Published
()
KEV added
AI analysis

CVE-2019-0541 is a remote code execution vulnerability caused by improper input validation in Microsoft's MSHTML engine, the component that renders HTML content inside Internet Explorer and embedded objects in Office documents. It is triggered when a user opens attacker-crafted content, such as a malicious web page viewed in Internet Explorer or a specially crafted Office document, and requires no privileges but does require user interaction (CVSS 3.1 vector AV:N/AC:L/PR:N/UI:R). A successful attacker gains arbitrary code execution in the context of the current user, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score of 8.8). Affected products include Internet Explorer 9, 10, and 11, Microsoft Office including Office 365 ProPlus, and the legacy Office Word Viewer and Excel Viewer, meaning virtually any Windows environment using these components is exposed. The flaw has been exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 and a public proof of concept exists — EPSS estimates a 53.2% probability of exploitation within 30 days (99th percentile), and it was fixed in Microsoft's January 2019 Patch Tuesday updates.

What to do: Apply Microsoft's January 2019 Patch Tuesday security updates immediately across all Windows, Internet Explorer, and Office installations (including Office 365 ProPlus), prioritizing endpoints required by CISA KEV's stated action to apply updates per vendor instructions. Remove or replace the end-of-life Office Word Viewer and Excel Viewer, and reduce reliance on Internet Explorer while warning users not to open untrusted documents or links, since user interaction is required for exploitation. Hunt for signs of compromise on unpatched systems, as the KEV listing confirms in-the-wild exploitation (ransomware use: unknown).

Affected
Microsoft Internet Explorer9, 10, and 11
Microsoft Office
Microsoft Office 365 ProPlus
Microsoft Office Word Viewer
Microsoft Excel Viewer
Estimated exposure
masshundreds of millions of endpoints (Internet Explorer 9–11 and Office are standard on most Windows systems; Office alone has on the order of 1 billion installs) — Estimated from the near-ubiquitous deployment of Internet Explorer and Microsoft Office on Windows in 2019 (Office exceeds one billion users and IE retained hundreds of millions of users), while noting that only users who open untrusted…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.

CISA Known Exploited Vulnerability
Affected
Microsoft MSHTML
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
internet explorer, excel viewer, office, office 365 proplus, office word viewer
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news