ZeroHour

CVE-2019-1163

CVSS 3.1
5.5 medium
EPSS
1%p72
Published
()
Modified
Description

A security feature bypass exists when Windows incorrectly validates CAB file signatures. An attacker who successfully exploited this vulnerability could inject code into a CAB file without invalidating the file's signature. To exploit the vulnerability, an attacker could modify a signed CAB file and inject malicious code. The attacker could then convince a target user to execute the file. The update addresses the vulnerability by correcting how Windows validates file signatures.

Vendors
microsoft
Products
windows 10, windows server 2016, windows server 2019
Weakness
CWE-354
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news