A security feature bypass exists when Windows incorrectly validates CAB file signatures. An attacker who successfully exploited this vulnerability could inject code into a CAB file without invalidating the file's signature.
To exploit the vulnerability, an attacker could modify a signed CAB file and inject malicious code. The attacker could then convince a target user to execute the file.
The update addresses the vulnerability by correcting how Windows validates file signatures.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-9735 A security feature bypass exists when Windows incorrectly validates CAB file signatures. An attacker who successfully exploited this vulnerability could inject code into a CAB file without invalidating the file's signature. To exploit the vulnerability, an attacker could modify a signed CAB file and inject malicious code. The attacker could then convince a target user to execute the file. The update addresses the vulnerability by correcting how Windows validates file signatures.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2024-08-04T18:06:31.833Z

Reserved: 2018-11-26T00:00:00

Link: CVE-2019-1163

cve-icon Vulnrichment

Updated: 2024-08-04T18:06:31.833Z

cve-icon NVD

Status : Modified

Published: 2019-08-14T21:15:15.703

Modified: 2024-11-21T04:36:09.223

Link: CVE-2019-1163

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.