CVE-2019-0985

Description

A remote code execution vulnerability exists when the Microsoft Speech API (SAPI) improperly handles text-to-speech (TTS) input, aka Microsoft Speech API Remote Code Execution Vulnerability.

Risk Information

Base Score
7.7
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
15.526

Associated Vulnerability

VulnerabilityOS Platform
Windows Kernel Information Disclosure Vulnerability for Windows 7 for x64-based Systems (KB4503269)Windows
Windows Kernel Information Disclosure Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4503269)Windows
Windows Kernel Information Disclosure Vulnerability for Windows 7 for x86-based Systems (KB4503269)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 7 for x86-based Systems (KB4503292)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 7 for x64-based Systems (KB4503292)Windows
Scripting Engine Memory Corruption Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4503292)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-268332019-06 Security Only Quality Update for Windows 7 for x64-based Systems (KB4503269)
PATCH-268342019-06 Security Only Quality Update for Windows Server 2008 R2 for x64-based Systems (KB4503269)
PATCH-268352019-06 Security Only Quality Update for Windows 7 for x86-based Systems (KB4503269)
PATCH-268422019-06 Security Monthly Quality Rollup for Windows 7 for x86-based Systems (KB4503292)
PATCH-268432019-06 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB4503292)
PATCH-268442019-06 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems (KB4503292)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234