CVE-2019-0985CriticalCVSS 7.8

Microsoft Speech API Remote Code Execution Vulnerability

Published
June 11, 2019
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A remote code execution vulnerability exists when the Microsoft Speech API (SAPI) improperly handles text-to-speech (TTS) input. The vulnerability could corrupt memory in a way that enables an attacker to execute arbitrary code in the context of the current user. To exploit the vulnerability, an attacker would need to convince a user to open a specially crafted document containing TTS content invoked through a scripting language. The update address the vulnerability by modifying how the system handles objects in memory.

🎯 Affected products5

  • Windows 7 for 32-bit Systems Service Pack 1
  • Windows 7 for x64-based Systems Service Pack 1
  • Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

✅ Remediation

KB4503292 (Monthly Rollup) KB4503269 (Security Only)

🔗 References (5)