CVE-2019-1155

high Microsoft
CVSS v3 Base Score
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
9.7%
Exploitation probability in 30 days
Top 7% most likely to be exploited
Attack Characteristics
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Confidentiality
High
Integrity
High
Availability
High
Published: August 14, 2019 (2465 days ago)
Last Modified: February 20, 2026
Vendor: Microsoft

Description

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory.

CWE

NVD-CWE-noinfo

Affected Products

microsoft officemicrosoft office 365 proplusmicrosoft windows 10microsoft windows 7microsoft windows 8.1microsoft windows rt 8.1microsoft windows server 2008microsoft windows server 2012microsoft windows server 2016microsoft windows server 2019

References