CVE-2019-0541 (CNNVD-201901-177)
中文标题:
Microsoft MSHTML引擎输入验证错误漏洞
英文标题:
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates ...
漏洞描述
中文描述:
Microsoft Internet Explorer等都是美国微软(Microsoft)公司的产品。Microsoft Internet Explorer(IE)是一款Web浏览器。Office 2010 SP2是一套办公套件。Microsoft MSHTML engine是其中的一个用于解析HTML语言的引擎。 Microsoft MSHTML引擎中存在输入验证漏洞,该漏洞源于程序没有正确地验证输入。远程攻击者可通过诱使用户编辑特制的文件利用该漏洞在当前用户的上下文中执行任意代码。以下产品和版本受到影响:Microsoft Internet Explorer 10,Internet Explorer 11,Internet Explorer 9;Excel Viewer 2007 SP3;Office 2010 SP2,Office 2013 RT SP1,Office 2013 SP1,Office 2016,Office 2019;Office Word Viewer;Office 365 ProPlus。
英文描述:
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Microsoft | Microsoft Office | 2010 Service Pack 2 (32-bit editions) | - | - |
cpe:2.3:a:microsoft:microsoft_office:2010_service_pack_2_(32-bit_editions):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | 2010 Service Pack 2 (64-bit editions) | - | - |
cpe:2.3:a:microsoft:microsoft_office:2010_service_pack_2_(64-bit_editions):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | 2013 RT Service Pack 1 | - | - |
cpe:2.3:a:microsoft:microsoft_office:2013_rt_service_pack_1:*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | 2013 Service Pack 1 (32-bit editions) | - | - |
cpe:2.3:a:microsoft:microsoft_office:2013_service_pack_1_(32-bit_editions):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | 2013 Service Pack 1 (64-bit editions) | - | - |
cpe:2.3:a:microsoft:microsoft_office:2013_service_pack_1_(64-bit_editions):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | 2016 (32-bit edition) | - | - |
cpe:2.3:a:microsoft:microsoft_office:2016_(32-bit_edition):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | 2016 (64-bit edition) | - | - |
cpe:2.3:a:microsoft:microsoft_office:2016_(64-bit_edition):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | 2019 for 32-bit editions | - | - |
cpe:2.3:a:microsoft:microsoft_office:2019_for_32-bit_editions:*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | 2019 for 64-bit editions | - | - |
cpe:2.3:a:microsoft:microsoft_office:2019_for_64-bit_editions:*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office Word Viewer | Microsoft Office Word Viewer | - | - |
cpe:2.3:a:microsoft:microsoft_office_word_viewer:microsoft_office_word_viewer:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 9 | Windows Server 2008 for 32-bit Systems Service Pack 2 | - | - |
cpe:2.3:a:microsoft:internet_explorer_9:windows_server_2008_for_32-bit_systems_service_pack_2:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 9 | Windows Server 2008 for x64-based Systems Service Pack 2 | - | - |
cpe:2.3:a:microsoft:internet_explorer_9:windows_server_2008_for_x64-based_systems_service_pack_2:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows 10 for 32-bit Systems | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_10_for_32-bit_systems:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows 10 for x64-based Systems | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_10_for_x64-based_systems:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows 10 Version 1607 for 32-bit Systems | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_10_version_1607_for_32-bit_systems:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows 10 Version 1607 for x64-based Systems | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_10_version_1607_for_x64-based_systems:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows 10 Version 1703 for 32-bit Systems | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_10_version_1703_for_32-bit_systems:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows 10 Version 1703 for x64-based Systems | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_10_version_1703_for_x64-based_systems:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows 10 Version 1709 for 32-bit Systems | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_10_version_1709_for_32-bit_systems:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows 10 Version 1709 for ARM64-based Systems | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_10_version_1709_for_arm64-based_systems:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows 10 Version 1709 for x64-based Systems | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_10_version_1709_for_x64-based_systems:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows 10 Version 1803 for 32-bit Systems | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_10_version_1803_for_32-bit_systems:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows 10 Version 1803 for ARM64-based Systems | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_10_version_1803_for_arm64-based_systems:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows 10 Version 1803 for x64-based Systems | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_10_version_1803_for_x64-based_systems:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows 10 Version 1809 for 32-bit Systems | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_10_version_1809_for_32-bit_systems:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows 10 Version 1809 for ARM64-based Systems | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_10_version_1809_for_arm64-based_systems:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows 10 Version 1809 for x64-based Systems | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_10_version_1809_for_x64-based_systems:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows 7 for 32-bit Systems Service Pack 1 | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_7_for_32-bit_systems_service_pack_1:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows 7 for x64-based Systems Service Pack 1 | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_7_for_x64-based_systems_service_pack_1:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows 8.1 for 32-bit systems | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_8.1_for_32-bit_systems:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows 8.1 for x64-based systems | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_8.1_for_x64-based_systems:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows RT 8.1 | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_rt_8.1:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows Server 2008 R2 for x64-based Systems Service Pack 1 | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_server_2008_r2_for_x64-based_systems_service_pack_1:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows Server 2012 R2 | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_server_2012_r2:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows Server 2016 | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_server_2016:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 11 | Windows Server 2019 | - | - |
cpe:2.3:a:microsoft:internet_explorer_11:windows_server_2019:*:*:*:*:*:*:*
|
| Microsoft | Microsoft Excel Viewer | 2007 Service Pack 3 | - | - |
cpe:2.3:a:microsoft:microsoft_excel_viewer:2007_service_pack_3:*:*:*:*:*:*:*
|
| Microsoft | Internet Explorer 10 | Windows Server 2012 | - | - |
cpe:2.3:a:microsoft:internet_explorer_10:windows_server_2012:*:*:*:*:*:*:*
|
| Microsoft | Office | 365 ProPlus for 32-bit Systems | - | - |
cpe:2.3:a:microsoft:office:365_proplus_for_32-bit_systems:*:*:*:*:*:*:*
|
| Microsoft | Office | 365 ProPlus for 64-bit Systems | - | - |
cpe:2.3:a:microsoft:office:365_proplus_for_64-bit_systems:*:*:*:*:*:*:*
|
| microsoft | internet_explorer | 11 | - | - |
cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*
|
| microsoft | excel_viewer | 2007 | - | - |
cpe:2.3:a:microsoft:excel_viewer:2007:sp3:*:*:*:*:*:*
|
| microsoft | office | 2010 | - | - |
cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*
|
| microsoft | office | 2013 | - | - |
cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:*
|
| microsoft | office | 2016 | - | - |
cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:*:*
|
| microsoft | office | 2019 | - | - |
cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:*
|
| microsoft | office_365_proplus | - | - | - |
cpe:2.3:a:microsoft:office_365_proplus:-:*:*:*:*:*:*:*
|
| microsoft | office_word_viewer | - | - | - |
cpe:2.3:a:microsoft:office_word_viewer:-:*:*:*:*:*:*:*
|
| microsoft | internet_explorer | 9 | - | - |
cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*
|
| microsoft | internet_explorer | 10 | - | - |
cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.1 (adp)
HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2019-0541 |
2025-11-11 15:19:56 | 2025-11-11 07:35:25 |
| NVD | nvd_CVE-2019-0541 |
2025-11-11 14:56:19 | 2025-11-11 07:43:58 |
| CNNVD | cnnvd_CNNVD-201901-177 |
2025-11-11 15:10:08 | 2025-11-11 07:54:17 |
| EXPLOITDB | exploitdb_EDB-46536 |
2025-11-11 15:05:53 | 2025-11-11 08:50:46 |
版本与语言
安全公告
变更历史
查看详细变更
- references_count: 4 -> 7
- tags_count: 0 -> 3
- data_sources: ['cnnvd', 'cve', 'nvd'] -> ['cnnvd', 'cve', 'exploitdb', 'nvd']
查看详细变更
- vulnerability_type: 未提取 -> 命令注入
- cnnvd_id: 未提取 -> CNNVD-201901-177
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 40 -> 50
- references_count: 3 -> 4
- data_sources: ['cve'] -> ['cve', 'nvd']