← Back

CVE-2019-1163

nvd nist
Published: Aug 14, 2019Modified: Jun 17, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Exploitability: 1.8 / Impact: 3.6
Source: secure@microsoft.com (Secondary)

Description

A security feature bypass exists when Windows incorrectly validates CAB file signatures. An attacker who successfully exploited this vulnerability could inject code into a CAB file without invalidating the file's signature. To exploit the vulnerability, an attacker could modify a signed CAB file and inject malicious code. The attacker could then convince a target user to execute the file. The update addresses the vulnerability by correcting how Windows validates file signatures.

Affected (11)

3 products
Windows 10
Windows Server 2016
Windows Server 2019
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
All versions
Version 1607
Version 1703
Version 1709
Version 1803
Version 1809
Version 1903
Microsoft
All versions
Version 1803
Version 1903
All versions

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.