CVE-2019-0838Sensitive Information Exposure in Microsoft Windows

6 documents4 sources
Severity
7.8HIGHNVD
NVD4.4
EPSS
0.4%
top 36.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 9
Latest updateMay 13

Description

An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses credentials to Windows Credential Manager, aka 'Windows Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0839.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages20 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8gfw-gh52-8w4c: An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses credentials to Windows Credential Manager, aka 'Window2022-05-13
GHSA
GHSA-mx3m-v5w7-425f: An information disclosure vulnerability exists when the Terminal Services component improperly discloses the contents of its memory, aka 'Windows Info2022-05-13

📋Vendor Advisories

2
Microsoft
Windows Information Disclosure Vulnerability2019-04-09
Red Hat
Struts2: Certain strings evaluated as OGNL expressions, leading to run-time data modification or arbitrary code execution2011-08-05
CVE-2019-0838 — Sensitive Information Exposure | cvebase