High severity8.8CISA KEVNVD Advisory· Published Jan 8, 2019· Updated Jun 17, 2026
CVE-2019-0541
CVE-2019-0541
Description
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
21cpe:2.3:a:microsoft:excel_viewer:2007:sp3:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microsoft:excel_viewer:2007:sp3:*:*:*:*:*:*
- (no CPE)range: 2007 Service Pack 3
cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: Windows Server 2012
- (no CPE)range: Windows 10 for 32-bit Systems
- (no CPE)range: Windows Server 2008 for 32-bit Systems Service Pack 2
cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2013:sp1:*:*:rt:*:*:*
- cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 365 ProPlus for 32-bit Systems
- cpe:2.3:a:microsoft:office_365_proplus:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_word_viewer:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microsoft:office_word_viewer:-:*:*:*:*:*:*:*
- (no CPE)range: Microsoft Office Word Viewer
- Range: 2010 Service Pack 2 (32-bit editions)
Patches
Vulnerability mechanics
References
4- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0541nvdPatchVendor Advisory
- www.exploit-db.com/exploits/46536/nvdExploitThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/106402nvdBroken LinkThird Party AdvisoryVDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.