CVE-2019-0633Microsoft Windows vulnerability

CWE-198 documents5 sources
Severity
8.8HIGHNVD
EPSS
35.8%
top 2.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 5
Latest updateMay 14

Description

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0630.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages18 packages

Patches

🔴Vulnerability Details

4
GHSA
GHSA-fmq9-923h-5cmq: A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 22022-05-14
GHSA
GHSA-9vjr-7mpv-6898: A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 22022-05-14
VulnCheck
Windows SMB Remote Code Execution2019
VulnCheck
Windows SMB Remote Code Execution2019

📋Vendor Advisories

1
Microsoft
Windows SMB Remote Code Execution Vulnerability2019-02-12

🕵️Threat Intelligence

1
Zscaler
Zscaler found Multiple Security Vulnerabilities | 02-12-2019
CVE-2019-0633 — Microsoft Windows vulnerability | cvebase