CVE-2019-1060

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.

Published : 2019-10-10 14:15 Updated : 2019-10-11 19:57

9.3
CVSS Score More info
Score 9.3 / 10
9.3
Vendor Product Version URI
Microsoft Windows 10 - cpe:/o:microsoft:windows_10:-
Microsoft Windows 10 1607 cpe:/o:microsoft:windows_10:1607
Microsoft Windows 10 1703 cpe:/o:microsoft:windows_10:1703
Microsoft Windows 10 1709 cpe:/o:microsoft:windows_10:1709
Microsoft Windows 10 1803 cpe:/o:microsoft:windows_10:1803
Microsoft Windows 10 1809 cpe:/o:microsoft:windows_10:1809
Microsoft Windows 10 1903 cpe:/o:microsoft:windows_10:1903
Microsoft Windows 8.1 - cpe:/o:microsoft:windows_8.1:-
Microsoft Windows Rt 8.1 - cpe:/o:microsoft:windows_rt_8.1:-
Microsoft Windows Server 2012 - cpe:/o:microsoft:windows_server_2012:-
Microsoft Windows Server 2012 r2 cpe:/o:microsoft:windows_server_2012:r2
Microsoft Windows Server 2016 - cpe:/o:microsoft:windows_server_2016:-
Microsoft Windows Server 2016 1803 cpe:/o:microsoft:windows_server_2016:1803
Microsoft Windows Server 2016 1903 cpe:/o:microsoft:windows_server_2016:1903
Microsoft Windows Server 2019 - cpe:/o:microsoft:windows_server_2019:-
  1. Microsoft (6) Search CVE
    1. Windows Rt 8.1 (1) Search CVE
      1. -
    2. Windows 10 (7) Search CVE
      1. -
      2. 1607
      3. 1703
      4. 1709
      5. 1803
      6. 1809
      7. 1903
    3. Windows 8.1 (1) Search CVE
      1. -
    4. Windows Server 2012 (2) Search CVE
      1. -
      2. R2
    5. Windows Server 2016 (3) Search CVE
      1. -
      2. 1803
      3. 1903
    6. Windows Server 2019 (1) Search CVE
      1. -

CWE

ID Name Description Links
CWE-611 Improper Restriction of XML External Entity Reference ('XXE') The software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. CVE

History of changes

Date Event
2019-10-11 19:57
2019-10-10 14:19

New CVE