CVE-2019-1119 is a remote code execution vulnerability in Microsoft DirectWrite, affecting Windows 10 and Windows Server 2019, stemming from improper handling of objects in memory. This high-severity flaw (CVSS 8.8) can be exploited remotely with low attack complexity, requiring user interaction, and potentially leading to complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, an ExploitDB entry (EDB-47092) details a stack corruption vulnerability related to OpenType font handling, suggesting public exploit code exists. Community discussion and media coverage indicate moderate attention to this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:* | ||
1803CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:* | ||
1809CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:* | ||
1903CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.