CVE-2019-0906: Microsoft Windows JET Database Engine Improper Validation of Array Index Remote Code Execution Vulnerability
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0904, CVE-2019-0905, CVE-2019-0907, CVE-2019-0908, CVE-2019-0909, CVE-2019-0974.
Other sources
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory.
— Microsoft
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the JET database engine. The issue results from the lack of proper validation of user-supplied data, which can result in memory access past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
— ZDI
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0906?
CVE-2019-0906 has a severity rating of critical, indicating that it poses a significant risk to affected systems.
How do I fix CVE-2019-0906?
To fix CVE-2019-0906, users should apply the latest security updates provided by Microsoft for their affected Windows systems.
What products are affected by CVE-2019-0906?
CVE-2019-0906 affects multiple versions of Microsoft Windows, including Windows 7, 8.1, and 10, as well as several Windows Server editions.
Can CVE-2019-0906 be exploited remotely?
Yes, CVE-2019-0906 is a remote code execution vulnerability, which means it can be exploited over a network without physical access to the affected machine.
What are the potential impacts of CVE-2019-0906?
The potential impacts of CVE-2019-0906 include unauthorized access and execution of malicious code on the vulnerable system.