CVE-2019-1123 is a remote code execution vulnerability in Microsoft DirectWrite, affecting Windows 10, Server 2016, and Server 2019. This high-severity flaw (CVSS 8.8) allows an unauthenticated attacker to execute arbitrary code if a user opens a specially crafted file or visits a malicious webpage, requiring user interaction. While not currently on the KEV catalog, public exploit code exists (EDB-47099), and it garnered some community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:* | ||
1803CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:* | ||
1809CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:* | ||
1903CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:* | ||
1803CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:1803:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.