CVE-2019-0628Sensitive Information Exposure in Microsoft Windows

4 documents4 sources
Severity
5.5MEDIUMNVD
EPSS
0.4%
top 38.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 5
Latest updateMay 13

Description

An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages20 packages

CVEListV5microsoft/windows20 versions+19
NVDmicrosoft/windowsr2, 1709, 1803+2

Patches

🔴Vulnerability Details

1
GHSA
GHSA-cp86-v3vp-pr4r: An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vu2022-05-13

📋Vendor Advisories

1
Microsoft
Win32k Information Disclosure Vulnerability2019-02-12

🕵️Threat Intelligence

1
Zscaler
Zscaler found Multiple Security Vulnerabilities | 02-12-2019
CVE-2019-0628 — Sensitive Information Exposure | cvebase