#VU21645 Input validation error in Windows Server and Windows - CVE-2019-1060
Published: October 8, 2019
Windows Server
Windows
Microsoft
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system
The vulnerability exists due to insufficient validation of user-supplied input within the the Microsoft XML Core Services MSXML parser. A remote attacker can create a specially crafted web page, trick the victim into visiting it and execute arbitrary code on the target system.