9.3
CVSSv2

CVE-2019-0791

Published: 09/04/2019 Updated: 11/04/2019
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0790, CVE-2019-0792, CVE-2019-0793, CVE-2019-0795.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows server 2008 -

microsoft windows rt 8.1 -

microsoft windows 8.1 -

microsoft windows 7 -

microsoft windows 10 -

microsoft windows server 2012 -

microsoft windows server 2008 r2

microsoft windows 10 1607

microsoft windows 10 1709

microsoft windows server 2012 r2

microsoft windows 10 1703

microsoft windows 10 1803

microsoft windows server 2019 -

microsoft windows server 2016 -

microsoft windows server 2016 1709

microsoft windows server 2016 1803

microsoft windows 10 1809

Recent Articles

Microsoft Patch Tuesday – April 2019
Symantec Threat Intelligence Blog • Himanshu Mehta • 10 Apr 2024

This month the vendor has patched 74 vulnerabilities, 14 of which are rated Critical.

Posted: 10 Apr, 201927 Min ReadThreat Intelligence SubscribeFollowtwitterfacebooklinkedinMicrosoft Patch Tuesday – April 2019This month the vendor has patched 74 vulnerabilities, 14 of which are rated Critical.As always, customers are advised to follow these security best practices: Install vendor patches as soon as they are available. Run all software with the least privileges required while still maintaining functionality. Avoid handlin...

It's raining patches, Hallelujah! Microsoft and Adobe put out their latest major fixes
The Register • Shaun Nichols in San Francisco • 09 Apr 2019

Hefty patch Tuesday checks in at just under 100 CVEs A patchy Apache a-patchin: HTTP server gets fix for worrying root access hole

Updated A pair of actively-targeted Windows flaws highlight this month's edition of Redmond's Patch Tuesday, the monthly moment when admins sigh and determine what to fix.. For Microsoft, the monthly flaw folder fixes for a total of 74 CVE-listed security bugs in Windows and Office. Of those, 33 are flaws which, if exploited, would allow the attacker to achieve remote code execution. As usual, most of the remote code execution flaws were spotted in the browser and scripting engines. Those includ...