Microsoft January 2019 Patch Tuesday updates fix 7 critical vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-0547 | A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka "Windows DHCP Clien A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka "Windows DHCP Client Remote Code Execution Vulnerability." This affects Windows 10, Windows 10 Servers. NVD description · AI analysis pending | 9.8 group max | 71% |
| — | ||
| CVE-2019-0537 | An information disclosure vulnerability exists when Visual Studio improperly discloses arbitrary file contents if the victim opens a malicious .vscontent file, An information disclosure vulnerability exists when Visual Studio improperly discloses arbitrary file contents if the victim opens a malicious .vscontent file, aka "Microsoft Visual Studio Information Disclosure Vulnerability." This affects Microsoft Visual Studio. NVD description · AI analysis pending | 5.5 | 8% |
| — | ||
| CVE-2019-0585 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Exec A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Microsoft SharePoint, Microsoft Office Online Server, Microsoft Word, Microsoft SharePoint Server. NVD description · AI analysis pending | 8.8 group max | 22% |
| — | ||
| CVE-2019-0539 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engi A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2019-0567, CVE-2019-0568. NVD description · AI analysis pending | 7.5 | 83% | PoC ×3 |
| — | |
| CVE-2019-0541 | Remote Code Execution in Microsoft MSHTML Engine (Office and Internet Explorer) CVE-2019-0541 is a remote code execution vulnerability caused by improper input validation in Microsoft's MSHTML engine, the component that renders HTML content inside Internet Explorer and embedded objects in Office documents. It is triggered when a user opens attacker-crafted content, such as a malicious web page viewed in Internet Explorer or a specially crafted Office document, and requires no privileges but does require user interaction (CVSS 3.1 vector AV:N/AC:L/PR:N/UI:R). A successful attacker gains arbitrary code execution in the context of the current user, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score of 8.8). Affected products include Internet Explorer 9, 10, and 11, Microsoft Office including Office 365 ProPlus, and the legacy Office Word Viewer and Excel Viewer, meaning virtually any Windows environment using these components is exposed. The flaw has been exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 and a public proof of concept exists — EPSS estimates a 53.2% probability of exploitation within 30 days (99th percentile), and it was fixed in Microsoft's January 2019 Patch Tuesday updates. Do: Apply Microsoft's January 2019 Patch Tuesday security updates immediately across all Windows, Internet Explorer, and Office installations (including Office 365 ProPlus), prioritizing endpoints required by CISA KEV's stated action to apply updates per vendor instructions. Remove or replace the end-of-life Office Word Viewer and Excel Viewer, and reduce reliance on Internet Explorer while warning users not to open untrusted documents or links, since user interaction is required for exploitation. Hunt for signs of compromise on unpatched systems, as the KEV listing confirms in-the-wild exploitation (ransomware use: unknown). | 8.8 | 53% | KEV PoC |
| masshundreds of millions of endpoints (Internet Explorer 9–11 and Office are standard on most Windows systems; Office alone has on the order of 1 billion installs) | |
| CVE-2019-0543 | Local Privilege Escalation (Improper Authentication) in Windows 7/8.1/10 and Server CVE-2019-0543 is an elevation-of-privilege flaw (CWE-287, improper authentication) that exists when Windows improperly handles authentication requests, affecting Windows 7, 8.1, RT 8.1, Windows 10 builds 1507 through 1809, and Windows Server 2008 through 2019. A local attacker who can already execute low-privileged code on a target machine can trigger the mishandled authentication handling with no user interaction and no special conditions (CVSS:3.1 AV:L/AC:L/PR:L/UI:N). Successful exploitation yields full control of the local system, with high confidentiality, integrity, and availability impact, so it is typically chained after an initial foothold such as phishing or malware. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-15 and notes known ransomware use; a public proof of concept is available (Exploit-DB 46156), and EPSS estimates a ~4.7% chance of exploitation in the next 30 days (91st percentile). Do: Apply Microsoft's January 2019 Patch Tuesday security updates (or any later cumulative update) across all affected Windows 7, 8.1, and 10 clients and Windows Server 2008-2019 hosts; organizations on Windows 7/Server 2008 R2 need Extended Security Update (ESU) coverage if still unpatched. Prioritize domain controllers, file servers, and internet-facing endpoints given the CISA KEV listing and known ransomware use, and since this is a post-foothold privilege escalation, also verify the initial-access vector (RCE/phishing) is remediated and monitor for local privilege-escalation activity. | 7.8 | 5% | KEV ransomware PoC |
| masshundreds of millions of devices (~10^8-10^9): effectively every Windows 7/8.1/10 client or Windows Server 2008-2019 host that lacked the January 2019 updates | |
| CVE-2019-0545 | An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka " An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7/4.7.1/4.7.2, .NET Core 2.1, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 2.2, Microsoft .NET Framework 4.7.2. NVD description · AI analysis pending | 7.5 | 10% |
| — | ||
| CVE-2019-0546 | A remote code execution vulnerability exists in Visual Studio when the C++ compiler improperly handles specific combinations of C++ constructs, aka "Visual Stud A remote code execution vulnerability exists in Visual Studio when the C++ compiler improperly handles specific combinations of C++ constructs, aka "Visual Studio Remote Code Execution Vulnerability." This affects Microsoft Visual Studio. NVD description · AI analysis pending | 7.8 | 16% |
| — | ||
| CVE-2019-0564 +1 in the same advisory: …0548 | A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548. NVD description · AI analysis pending | 7.5 | 8% |
| — | ||
| CVE-2019-0557 +1 in the same advisory: …0556 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected Sha A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2019-0556, CVE-2019-0558. NVD description · AI analysis pending | 5.4 | 2% |
| — | ||
| CVE-2019-0558 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected Sha A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint, Microsoft Business Productivity Servers. This CVE ID is unique from CVE-2019-0556, CVE-2019-0557. NVD description · AI analysis pending | 5.4 | 2% |
| — | ||
| CVE-2019-0562 | An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected ShareP An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. NVD description · AI analysis pending | 5.4 | 2% |
| — | ||
| CVE-2019-0566 +1 in the same advisory: …0565 | An elevation of privilege vulnerability exists in Microsoft Edge Browser Broker COM object, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affe An elevation of privilege vulnerability exists in Microsoft Edge Browser Broker COM object, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. NVD description · AI analysis pending | 8.8 group max | 19% | PoC |
| — | |
| CVE-2019-0586 +1 in the same advisory: …0588 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchang A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. NVD description · AI analysis pending | 9.8 group max | 15% |
| — | ||
| CVE-2019-0622 | An elevation of privilege vulnerability exists when Skype for Andriod fails to properly handle specific authentication requests, aka "Skype for Android Elevatio An elevation of privilege vulnerability exists when Skype for Andriod fails to properly handle specific authentication requests, aka "Skype for Android Elevation of Privilege Vulnerability." This affects Skype 8.35. NVD description · AI analysis pending | 4.6 | 2% |
| — |
Full article986 words · extracted from securityaffairs.com · click to collapse

Microsoft has released the January 2019 Patch Tuesday updates that address 51 vulnerabilities in Windows OSs and other products.
Microsoft has released Microsoft January 2019 Patch Tuesday that solve 51 vulnerabilities in Windows operating system and in the following solutions:
- Adobe Flash Player
- Internet Explorer
- Microsoft Edge
- Microsoft Windows
- Microsoft Office and Microsoft Office Services and Web Apps
- ChakraCore
- .NET Framework
- ASP.NET
- Microsoft Exchange Server
- Microsoft Visual Studio
A close look at the list of issues addressed with the Microsoft January 2019 Patch Tuesday reveals that 7 flaws are rated critical, none was exploited in attacks in the wild.
The vulnerabilities rated as critical could be exploited by attackers for remote code execution, most of them affect Windows 10 and Server editions.
Three out of seven critical issues affect the ChakraCore scripting engine in the Edge browser, two affect Microsoft’s Hyper-V server virtualization environment, one impacts Edge, and one affects the Windows DHCP client.
The CVE-2019-0547 vulnerability resides in the Mitch Adair of the Microsoft Windows Enterprise Security Team, it could be exploited by an attacker to send a specially crafted DHCP response to a client in order to perform arbitrary code execution.
“A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client. An attacker who successfully exploited the vulnerability could run arbitrary code on the client machine.” reads the security advisory.
“To exploit the vulnerability, an attacker could send a specially crafted DHCP responses to a client. The security update addresses the vulnerability by correcting how Windows DHCP clients handle certain DHCP responses.”
Other two Windows Hyper-V vulnerabilities (CVE-2019-0550 & CVE-2019-0551) can lead to remotely execute code on the host.
“A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system.” reads the security advisory related to the
CVE-2019-055 issue. “To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary code.”
Only one of the issues addressed with Microsoft January 2019 Patch Tuesday that resides in the Microsoft JET Database Engine was publicly known, but it was not exploited in the wild.
The flaw tracked as CVE-2019-0579 and rated as important could be exploited to execute arbitrary code on a target’s system by tricking users into opening a specially-crafted file.
The tech giant also fixed a vulnerability in Skype for Android (CVE-2019-0622) that could have allowed a local attacker with physical access to an Android device to bypass the lock screen and potentially expose victim’s data.
Below there is the full list of vulnerabilities addressed by the Microsoft January 2019 Patch Tuesday.
| Tag | CVE ID | CVE Title |
|---|---|---|
| .NET Framework | CVE-2019-0545 | .NET Framework Information Disclosure Vulnerability |
| Adobe Flash Player | ADV190001 | January 2019 Adobe Flash Update |
| Android App | CVE-2019-0622 | Skype for Android Elevation of Privilege Vulnerability |
| ASP.NET | CVE-2019-0548 | ASP.NET Core Denial of Service Vulnerability |
| ASP.NET | CVE-2019-0564 | ASP.NET Core Denial of Service Vulnerability |
| Internet Explorer | CVE-2019-0541 | MSHTML Engine Remote Code Execution Vulnerability |
| Microsoft Edge | CVE-2019-0565 | Microsoft Edge Memory Corruption Vulnerability |
| Microsoft Edge | CVE-2019-0566 | Microsoft Edge Elevation of Privilege Vulnerability |
| Microsoft Exchange Server | CVE-2019-0586 | Microsoft Exchange Memory Corruption Vulnerability |
| Microsoft Exchange Server | CVE-2019-0588 | Microsoft Exchange Information Disclosure Vulnerability |
| Microsoft JET Database Engine | CVE-2019-0576 | Jet Database Engine Remote Code Execution Vulnerability |
| Microsoft JET Database Engine | CVE-2019-0538 | Jet Database Engine Remote Code Execution Vulnerability |
| Microsoft JET Database Engine | CVE-2019-0575 | Jet Database Engine Remote Code Execution Vulnerability |
| Microsoft JET Database Engine | CVE-2019-0577 | Jet Database Engine Remote Code Execution Vulnerability |
| Microsoft JET Database Engine | CVE-2019-0582 | Jet Database Engine Remote Code Execution Vulnerability |
| Microsoft JET Database Engine | CVE-2019-0583 | Jet Database Engine Remote Code Execution Vulnerability |
| Microsoft JET Database Engine | CVE-2019-0584 | Jet Database Engine Remote Code Execution Vulnerability |
| Microsoft JET Database Engine | CVE-2019-0581 | Jet Database Engine Remote Code Execution Vulnerability |
| Microsoft JET Database Engine | CVE-2019-0578 | Jet Database Engine Remote Code Execution Vulnerability |
| Microsoft JET Database Engine | CVE-2019-0579 | Jet Database Engine Remote Code Execution Vulnerability |
| Microsoft JET Database Engine | CVE-2019-0580 | Jet Database Engine Remote Code Execution Vulnerability |
| Microsoft Office | CVE-2019-0560 | Microsoft Office Information Disclosure Vulnerability |
| Microsoft Office | CVE-2019-0561 | Microsoft Word Information Disclosure Vulnerability |
| Microsoft Office | CVE-2019-0585 | Microsoft Word Remote Code Execution Vulnerability |
| Microsoft Office | CVE-2019-0559 | Microsoft Outlook Information Disclosure Vulnerability |
| Microsoft Office SharePoint | CVE-2019-0562 | Microsoft SharePoint Elevation of Privilege Vulnerability |
| Microsoft Office SharePoint | CVE-2019-0556 | Microsoft Office SharePoint XSS Vulnerability |
| Microsoft Office SharePoint | CVE-2019-0558 | Microsoft Office SharePoint XSS Vulnerability |
| Microsoft Office SharePoint | CVE-2019-0557 | Microsoft Office SharePoint XSS Vulnerability |
| Microsoft Scripting Engine | CVE-2019-0568 | Chakra Scripting Engine Memory Corruption Vulnerability |
| Microsoft Scripting Engine | CVE-2019-0567 | Chakra Scripting Engine Memory Corruption Vulnerability |
| Microsoft Scripting Engine | CVE-2019-0539 | Chakra Scripting Engine Memory Corruption Vulnerability |
| Microsoft Windows | CVE-2019-0574 | Windows Data Sharing Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2019-0573 | Windows Data Sharing Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2019-0571 | Windows Data Sharing Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2019-0572 | Windows Data Sharing Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2019-0543 | Microsoft Windows Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2019-0570 | Windows Runtime Elevation of Privilege Vulnerability |
| Microsoft XML | CVE-2019-0555 | Microsoft XmlDocument Elevation of Privilege Vulnerability |
| Servicing Stack Updates | ADV990001 | Latest Servicing Stack Updates |
| Visual Studio | CVE-2019-0537 | Microsoft Visual Studio Information Disclosure Vulnerability |
| Visual Studio | CVE-2019-0546 | Visual Studio Remote Code Execution Vulnerability |
| Windows COM | CVE-2019-0552 | Windows COM Elevation of Privilege Vulnerability |
| Windows DHCP Client | CVE-2019-0547 | Windows DHCP Client Remote Code Execution Vulnerability |
| Windows Hyper-V | CVE-2019-0550 | Windows Hyper-V Remote Code Execution Vulnerability |
| Windows Hyper-V | CVE-2019-0551 | Windows Hyper-V Remote Code Execution Vulnerability |
| Windows Kernel | CVE-2019-0569 | Windows Kernel Information Disclosure Vulnerability |
| Windows Kernel | CVE-2019-0536 | Windows Kernel Information Disclosure Vulnerability |
| Windows Kernel | CVE-2019-0554 | Windows Kernel Information Disclosure Vulnerability |
| Windows Kernel | CVE-2019-0549 | Windows Kernel Information Disclosure Vulnerability |
| Windows Subsystem for Linux | CVE-2019-0553 | Windows Subsystem for Linux Information Disclosure Vulnerability |
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – Cybersecurity, Microsoft January 2019 Patch Tuesday)
[adrotate banner=”5″] [adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/79671/security/january-2019-patch-tuesday.html