CVE-2019-0541
CVE-2019-0541 is a high-severity vulnerability in Microsoft Internet Explorer with a CVSS 3.x base score of 8.8. It is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming it has been exploited in the wild (added 2021-11-03). The underlying weakness is classified as CWE-77.
Key facts
- Severity: High (CVSS 3.x base score 8.8)
- CVSS v2: 9.3
- EPSS exploit prediction: 53% (99th percentile)
- Actively exploited: Yes — listed in CISA KEV (added 2021-11-03)
- EU (EUVD) id: EUVD-2019-1313
- EU exploitation: Flagged exploited in the ENISA EU Vulnerability Database (since 2021-11-03)
- Weakness: CWE-77
- Affected product: Microsoft Internet Explorer
- Published:
- Last modified:
Description
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.
Frequently asked questions
- What is CVE-2019-0541?
- A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.
- How severe is CVE-2019-0541?
- CVE-2019-0541 has a CVSS 3.x base score of 8.8, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2019-0541 being actively exploited?
- Yes. CVE-2019-0541 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, added on 2021-11-03, which means active exploitation has been confirmed. It should be prioritised for remediation.
- What products are affected by CVE-2019-0541?
- CVE-2019-0541 primarily affects Microsoft Internet Explorer. In total, 11 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2019-0541?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Because this CVE is known to be actively exploited, treat remediation as urgent — CISA KEV typically sets a short remediation deadline.
- Does CVE-2019-0541 have an EU (EUVD) identifier?
- Yes. CVE-2019-0541 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2019-1313. It is also flagged as exploited in the EUVD (since 2021-11-03).
- When was CVE-2019-0541 published?
- CVE-2019-0541 was published on 2019-01-08 and last updated on 2026-06-17.
References
- http://www.securityfocus.com/bid/106402
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0541
- https://www.exploit-db.com/exploits/46536/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0541
Affected products (11)
- cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:excel_viewer:2007:sp3:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2013:sp1:*:*:rt:*:*:*
- cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office_365_proplus:-:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office_word_viewer:-:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*
More vulnerabilities in Microsoft Internet Explorer
- CVE-2014-1764 — Critical (CVSS 10.0): Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code and bypass a sandbox…
- CVE-2014-1763 — Critical (CVSS 10.0): Use-after-free vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary…
- CVE-2010-1118 — Critical (CVSS 10.0): Unspecified vulnerability in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to execute arbitrary…
- CVE-2009-1918 — Critical (CVSS 10.0): Microsoft Internet Explorer 5.01 SP4 and 6 SP1; Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2; and…
- CVE-2009-1043 — Critical (CVSS 10.0): Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary…
- CVE-2007-3341 — Critical (CVSS 10.0): Unspecified vulnerability in the FTP implementation in Microsoft Internet Explorer allows remote attackers to "see a…
All CVEs affecting Microsoft Internet Explorer →
Other CWE-77 (Command Injection) vulnerabilities
- CVE-2025-70518 — Critical (CVSS 10.0): The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied…
- CVE-2026-105484 — Critical (CVSS 10.0): A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the…
- CVE-2026-105134 — Critical (CVSS 10.0): A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file…
- CVE-2026-102240 — Critical (CVSS 10.0): A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file…
- CVE-2026-101076 — Critical (CVSS 10.0): A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file…
- CVE-2026-101075 — Critical (CVSS 10.0): A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of…