CVE-2019-0985CriticalCVSS 7.8
Microsoft Speech API Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
A remote code execution vulnerability exists when the Microsoft Speech API (SAPI) improperly handles text-to-speech (TTS) input. The vulnerability could corrupt memory in a way that enables an attacker to execute arbitrary code in the context of the current user. To exploit the vulnerability, an attacker would need to convince a user to open a specially crafted document containing TTS content invoked through a scripting language. The update address the vulnerability by modifying how the system handles objects in memory.
🎯 Affected products5
- Windows 7 for 32-bit Systems Service Pack 1
- Windows 7 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
✅ Remediation
KB4503292 (Monthly Rollup) KB4503269 (Security Only)
🔗 References (5)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-0985
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4503292
- referencehttps://support.microsoft.com/help/4503292
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4503269
- referencehttps://support.microsoft.com/help/4503269