High severity7.5NVD Advisory· Published Sep 11, 2019· Updated Jun 17, 2026
CVE-2019-1236
CVE-2019-1236
Description
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1208.
Affected products
24cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
Windows Server 2012+ 2 more
- (no CPE)range: Windows Server 2012
- (no CPE)range: Windows 7 for 32-bit Systems Service Pack 1
- (no CPE)range: Windows Server 2008 for 32-bit Systems Service Pack 2
- Microsoft/Internet Explorer 11 on Windows 10 Version 1903 for 32-bit Systemsv5Range: unspecified
- Microsoft/Internet Explorer 11 on Windows 10 Version 1903 for ARM64-based Systemsv5Range: unspecified
- Microsoft/Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systemsv5Range: unspecified
- Microsoft/Internet Explorer 11 on Windows Server 2012v5Range: unspecified
Patches
Vulnerability mechanics
References
1- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1236nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.