CVE-2019-1430 is a remote code execution vulnerability in Microsoft Windows Media Foundation, affecting Windows 10 and Windows Server 2016. It arises from improper parsing of specially crafted QuickTime media files, allowing an attacker to gain the same user rights as the local user. With a CVSS score of 7.8 (High), it requires user interaction (UI:R) but has low attack complexity (AC:L) and can lead to high impact on confidentiality, integrity, and availability. While it has a high FAUCET Risk Score of 95/100 and an elevated EPSS score, there is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and limited community discussion or media coverage beyond initial patch reporting.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1903CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:* | ||
1903CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:1903:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.