CVE-2019-1430

HIGH

Windows 10 and Windows Server 2016 - Remote Code Execution via QuickTime Media File Parsing

Title source: llm
STIX 2.1

Description

A remote code execution vulnerability exists when Windows Media Foundation improperly parses specially crafted QuickTime media files.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'Microsoft Windows Media Foundation Remote Code Execution Vulnerability'.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.1296
EPSS Percentile 95.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

Status published
Products (2)
microsoft/windows_10 1903
microsoft/windows_server_2016 1903
Published Nov 12, 2019
Tracked Since Feb 18, 2026