HIGH CISA KEV

CVE-2019-0541

CVSS v3

8.8

HIGH

EPSS Score

80.9%

exploit probability

CISA KEV

Yes

known exploited

Exploitation

SSVC status

Description

A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.

CISA Known Exploited Vulnerability

Date Added
11/3/2021
Patch Due Date
5/3/2022
Ransomware Use
Unknown

Technical details

Published
1/8/2019

Frequently asked questions

What is CVE-2019-0541?

A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.

Is CVE-2019-0541 actively exploited?

Yes. CVE-2019-0541 is on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning it has been confirmed as actively exploited in the wild. CISA requires federal agencies to patch by 5/3/2022.

What is the CVSS score for CVE-2019-0541?

CVE-2019-0541 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2019-0541 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.