CVE-2019-0719Improper Input Validation in Microsoft Windows

Severity
9.1CRITICALNVD
EPSS
1.4%
top 19.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12
Latest updateMay 24

Description

A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0721.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HExploitability: 2.3 | Impact: 6.0

Affected Packages5 packages

CVEListV5microsoft/windows_server13 versions+12
CVEListV5microsoft/windows6 versions+5
NVDmicrosoft/windowsr2, 1803, 1903+2
NVDmicrosoft/windows_105 versions+4

Patches

🔴Vulnerability Details

4
GHSA
GHSA-c9x8-4v35-37qf: A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticat2022-05-24
GHSA
GHSA-wgjq-j646-4ghv: A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticat2022-05-24
CVEList
CVE-2019-0721: A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticat2019-11-12
CVEList
CVE-2019-0719: A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticat2019-11-12

💥Exploits & PoCs

1
Exploit-DB
Kramer VIAware 2.5.0719.1034 - Remote Code Execution (RCE)2022-03-30

📋Vendor Advisories

1
Microsoft
Hyper-V Remote Code Execution Vulnerability2019-11-12

🕵️Threat Intelligence

2
Talos
Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage2019-08-13
Talos
Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage2019-08-13
CVE-2019-0719 — Improper Input Validation in Microsoft | cvebase