CVE-2019-1163: Microsoft Windows 10
Medium severity, CVSS 5.5. EPSS: 1.5% chance of exploitation in the next 30 days.
A security feature bypass exists when Windows incorrectly validates CAB file signatures. An attacker who successfully exploited this vulnerability could inject code into a CAB file without invalidating the file's signature. To exploit the vulnerability, an attacker could modify a signed CAB file and inject malicious code. The attacker could then convince a target user to execute the file. The update addresses the vulnerability by correcting how Windows validates file signatures.
Affected products
- Microsoft Windows 10: affected versions not specified; version 1607 only; version 1703 only; version 1709 only; version 1803 only; version 1809 only; …
- Microsoft Windows Server 2016: affected versions not specified; version 1803 only; version 1903 only
- Microsoft Windows Server 2019: affected versions not specified
Published 2019-08-14. Last modified 2026-06-17.