CVE-2019-0948
MEDIUM 5.5EPSS 12.7%
An information disclosure vulnerability exists in the Windows Event Viewer (eventvwr.msc) when it improperly parses XML input containing a reference to an external entity. An attacker who successfully exploited this vulnerability could read arbitrary files via an XML external entity (XXE) declaration.To exploit the vulnerability, an attacker could create a file containing specially crafted XML content and convince an authenticated user to import the file.The update addresses the vulnerability by modifying the way that the Event Viewer parses XML input.
- CVSS v3.1
- 4.7 MEDIUM
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N - CVSS v3.0
- 5.5 MEDIUM
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N - EPSS
- 12.67% chance of exploitation in the next 30 days, 96th percentile
- Published
- 2019-06-12
- Updated
- 2025-05-20