Permissions, Privileges, and Access Controls in Microsoft Windows and Windows Server - CVE-2019-0555
Published: January 8, 2019
Vulnerability identifier: #VU16875
CSH Severity: Medium
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0555
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists within the Microsoft XmlDocument class. A remote attacker can bypass the AppContainer sandbox in the browser and perform actions on the system with elevated privileges in conjunction with other vulnerabilities.
Affected software
Microsoft Windows
Windows Server
Windows Server
How to mitigate CVE-2019-0555
Install updates from vendor's website.