CVE-2019-0838
published 2019-04-09CVE-2019-0838: An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses credentials to Windows Credential Manager, aka 'Windows…
PriorityP337high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
2.06%
79.3th percentile
An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses credentials to Windows Credential Manager, aka 'Windows Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0839.
Affected
61 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat10.0CRITICAL
vendor_msrc6.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Information Disclosure Vulnerability
vendor_msrc·2019-04-09·CVSS 6.6
CVE-2019-0838 [HIGH] Windows Information Disclosure Vulnerability
Windows Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses credentials to Windows Credential Manager. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability.
The security update addresses the vulnerability by changing how Task Scheduler handles credentials.
FAQ: What type of information could be disclosed by this vulnerability?
The t
Red Hat
Struts2: Certain strings evaluated as OGNL expressions, leading to run-time data modification or arbitrary code execution
vendor_redhat·2011-08-05·CVSS 10.0
CVE-2012-0838 [CRITICAL] Struts2: Certain strings evaluated as OGNL expressions, leading to run-time data modification or arbitrary code execution
Struts2: Certain strings evaluated as OGNL expressions, leading to run-time data modification or arbitrary code execution
Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.
Statement: A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat provided final products, and does not cause any vulnerability in the product, struts2-core jars have been included in some products' source code packages.
GHSA
GHSA-8gfw-gh52-8w4c: An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses credentials to Windows Credential Manager, aka 'Window
ghsa_unreviewed·2022-05-13·CVSS 4.4
CVE-2019-0838 [MEDIUM] GHSA-8gfw-gh52-8w4c: An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses credentials to Windows Credential Manager, aka 'Window
An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses credentials to Windows Credential Manager, aka 'Windows Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0839.
GHSA
GHSA-mx3m-v5w7-425f: An information disclosure vulnerability exists when the Terminal Services component improperly discloses the contents of its memory, aka 'Windows Info
ghsa_unreviewed·2022-05-13·CVSS 7.8
CVE-2019-0839 [HIGH] GHSA-mx3m-v5w7-425f: An information disclosure vulnerability exists when the Terminal Services component improperly discloses the contents of its memory, aka 'Windows Info
An information disclosure vulnerability exists when the Terminal Services component improperly discloses the contents of its memory, aka 'Windows Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0838.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-04-09
Published