Vulnerability record · CVE-2019-0541 · published 8 January 2019
CVE-2019-0541: Microsoft MSHTML engine input validation flaw allows remote code execution
Microsoft · Internet Explorer
The MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Because MSHTML is a shared rendering component, the flaw reaches a wide set of Microsoft products and is listed in CISA's Known Exploited Vulnerabilities catalog.
Description
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is remotely reachable, leads to full code execution, is listed in CISA KEV and has public exploit code, though it requires user interaction.
What it is
The MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Because MSHTML is a shared rendering component, the flaw reaches a wide set of Microsoft products and is listed in CISA's Known Exploited Vulnerabilities catalog.
Impact
An attacker who convinces a user to open crafted content can execute arbitrary code in the context of the affected application, giving full control of confidentiality, integrity and availability on the victim host.
Attack surface
Reached over the network via crafted content rendered by MSHTML, such as a malicious document or web page. The CVSS vector shows no privileges required but user interaction is required, so the victim must open or view the malicious content.
Exploitation
CVE-2019-0541 is in CISA's KEV catalog with a 30-day EPSS probability of about 0.53 (98.9th percentile), and a public Exploit-DB entry exists, indicating active exploitation and available exploit code.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for all affected products, including Office, Office 365 ProPlus, Internet Explorer and the Office viewers.
- Prioritize patching per CISA KEV remediation guidance given the confirmed exploitation.
- Restrict or disable unnecessary MSHTML-based rendering paths and legacy viewers where business use does not require them.
- Enforce email and web filtering to block crafted documents and pages that target the MSHTML engine.
- Reduce user exposure by disabling or uninstalling unsupported viewers such as Word Viewer and Excel Viewer.
Detection
- Monitor for Office or Internet Explorer processes spawning unexpected child processes such as scripting hosts or command shells.
- Alert on document or web content delivery from untrusted sources that triggers MSHTML rendering in Office or IE.
- Hunt for known Exploit-DB 46536 indicators and related payload behavior in endpoint telemetry.
- Review proxy and email logs for delivery of crafted files matching MSHTML exploitation patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-0541 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft MSHTML Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/106402 | Broken LinkThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0541 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/46536/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/106402 | Broken LinkThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0541 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/46536/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0541 | US Government Resource |
Track CVE-2019-0541 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-0541), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.