Researchers disclosed two Microsoft Jet Database Engine vulnerabilities, CVE-2019-1406 and CVE-2019-1250, that can lead to remote code execution when a user opens a specially crafted MDB database file on affected Windows systems. The flaws affect Windows 7 through Windows 10 version 1903 and below and involve the Jet components msjet40.dll and msrd3x40.dll, where malformed database content can corrupt memory and redirect execution flow.
In the CVE-2019-1406 case, STAR Labs said type confusion during ErrOpenDatabase and TblPage::CreateLvSMLocs can make the engine treat attacker-controlled data as a ColumnLvText object, with proof-of-concept analysis showing control of execution through an arbitrary address. For CVE-2019-1250, the researchers traced memory corruption to msrd3x40!Record::IsNull after crafted changes to the database version field altered Jet/Red ISAM processing and reached vulnerable record-retrieval paths. Microsoft was notified of both issues and released patches, later acknowledging the vulnerabilities in its MSRC advisories.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
STAR Labs disclosed analysis of CVE-2019-1406, a type-confusion remote code execution flaw in msjet40.dll. The advisory showed that a malicious MDB file could make the engine dereference attacker-controlled data, with a proof of concept demonstrating control of EIP.
Microsoft patched both Jet Database Engine vulnerabilities and acknowledged them in MSRC advisories. The fixes addressed code-execution risks in msrd3x40.dll and msjet40.dll affecting Windows 7 through Windows 10 version 1903 and below.
STAR Labs disclosed analysis of CVE-2019-1250, a memory-corruption/code-execution flaw in the Microsoft Jet Database Engine's msrd3x40.dll component. The write-up described how a crafted MDB file could alter execution flow and reach the vulnerable Record::IsNull path.
STAR Labs notified Microsoft of two code-execution flaws in the Microsoft Jet Database Engine, later assigned CVE-2019-1250 and CVE-2019-1406. Both issues could be triggered by opening specially crafted MDB database files on supported Windows versions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.