Permissions, Privileges, and Access Controls in Microsoft Windows and Windows Server - CVE-2019-0555

 

Permissions, Privileges, and Access Controls in Microsoft Windows and Windows Server - CVE-2019-0555

Published: January 8, 2019


Vulnerability identifier: #VU16875
CSH Severity: Medium
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0555
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists within the Microsoft XmlDocument class. A remote attacker can bypass the AppContainer sandbox in the browser and perform actions on the system with elevated privileges in conjunction with other vulnerabilities.



Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2019-0555

Install updates from vendor's website.


External References

Related Security Bulletins