CVE Published: 14/08/2019 |
CVE Updated: 04/08/2024 |
CVE Year: 2019 Source: microsoft |
Vendor: Microsoft |
Product: Windows 10 Version 1703 Status : PUBLISHED
CVE-2019-1163 Description
A security feature bypass exists when Windows incorrectly validates CAB file signatures. An attacker who successfully exploited this vulnerability could inject code into a CAB file without invalidating the file\'s signature.
To exploit the vulnerability, an attacker could modify a signed CAB file and inject malicious code. The attacker could then convince a target user to execute the file.
The update addresses the vulnerability by correcting how Windows validates file signatures.
Metrics
CVSS Version: 3.1 |
Base Score: 5.5 MEDIUM Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C