Vulnerability record · CVE-2019-1358 · published 10 October 2019
CVE-2019-1358: Windows Jet Database Engine memory handling remote code execution
Microsoft · Windows 10
The Windows Jet Database Engine mishandles objects in memory, allowing an attacker to execute code in the context of the current user. It affects a broad set of Windows client and server releases, so unpatched systems running the engine are exposed. The record gives no root-cause detail beyond improper memory handling.
Description
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1359.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 and a 99.5th percentile EPSS score indicate serious impact and high predicted exploitation, though no KEV listing or public exploit is recorded.
What it is
The Windows Jet Database Engine mishandles objects in memory, allowing an attacker to execute code in the context of the current user. It affects a broad set of Windows client and server releases, so unpatched systems running the engine are exposed. The record gives no root-cause detail beyond improper memory handling.
Impact
An attacker who gets code to run gains the privileges of the logged-on user, which can mean full control of the system if that user is an administrator. This enables data theft, persistence and further lateral movement.
Attack surface
The CVSS vector is local (AV:L) with user interaction required (UI:R) and no privileges needed (PR:N), so the flaw is reached by convincing a user to open a crafted file or otherwise trigger the Jet engine locally. No authentication is required, but interaction is.
Exploitation
CISA KEV does not list this CVE, and the only references are Microsoft patch advisories, so there is no public evidence of exploitation in the record. EPSS is high at 0.765 (99.5th percentile), indicating elevated predicted exploitation likelihood.
What to do
- Apply the Microsoft security update for CVE-2019-1358 to all affected Windows versions.
- Restrict opening of untrusted Jet/Access database files and email attachments that could invoke the engine.
- Enforce least privilege so users do not run as administrators, limiting the impact of code execution.
- Track patch compliance for Windows 7, 8.1, RT 8.1, 10 and the listed Server releases.
Detection
- Monitor for unexpected processes spawning from Office or database applications that load the Jet engine.
- Alert on creation or execution of suspicious .mdb/.accdb files from email or download directories.
- Review endpoint telemetry for memory-corruption crash patterns in Jet-related modules.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1358 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1358 | PatchVendor Advisory |
Track CVE-2019-1358 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-1358), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.