CVE-2019-0541: Microsoft MSHTML Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.
Other sources
Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-0541?
CVE-2019-0541 is a remote code execution vulnerability in the MSHTML engine that affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, and Internet Explorer 10.
How severe is CVE-2019-0541?
CVE-2019-0541 has a severity rating of 8.8, which is considered critical.
Which software is affected by CVE-2019-0541?
CVE-2019-0541 affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, and Internet Explorer 10.
How can I fix CVE-2019-0541?
To fix CVE-2019-0541, apply the latest security updates and patches provided by Microsoft.
Where can I find more information about CVE-2019-0541?
You can find more information about CVE-2019-0541 on the SecurityFocus website (http://www.securityfocus.com/bid/106402) and the Microsoft Security Guidance Advisory (https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0541).