CVE Feed

    Dashboard / CVE / CVE-2019-1188

    CVE-2019-1188

    A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The attacker could present to the user a removable drive, or remote share, that contains a malicious .LNK file and an associated malicious binary. When the user opens this drive(or remote share) in Windows Explorer, or any other application that parses the .LNK file, the malicious binary will execute code of the attacker’s choice, on the target system. The security update addresses the vulnerability by correcting the processing of shortcut LNK references.

    Published:Aug 14, 2019
    Last Modified:Feb 20, 2026
    EPS:Aug 14, 2019
    EPSS Score:0.06062
    CVSS Score:7.5

    Affected Products

    Vendor
    Microsoft
    Product
    Windows 10
    Vendor
    Microsoft
    Product
    Windows 10 1803
    Vendor
    Microsoft
    Product
    Windows 10 1809
    Vendor
    Microsoft
    Product
    Windows Server 1803
    Vendor
    Microsoft
    Product
    Windows Server 1903
    Vendor
    Microsoft
    Product
    Windows Server 2016
    Vendor
    Microsoft
    Product
    Windows Server 2019

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High