CVE-2019-0865Microsoft Windows vulnerability

6 documents5 sources
Severity
7.5HIGHNVD
EPSS
8.6%
top 7.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15
Latest updateMay 24

Description

A denial of service vulnerability exists when SymCrypt improperly handles a specially crafted digital signature.An attacker could exploit the vulnerability by creating a specially crafted connection or message.The security update addresses the vulnerability by correcting the way SymCrypt handles digital signatures., aka 'SymCrypt Denial of Service Vulnerability'.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages24 packages

CVEListV5microsoft/windows11 versions+10
NVDmicrosoft/windows1803, 1903+1
NVDmicrosoft/windows_105 versions+4
CVEListV5microsoft/windows_server2019, 2019 (Core installation), version 1803 (Core Installation)+2

Patches

🔴Vulnerability Details

1
GHSA
GHSA-q29g-c7pw-v72q: A denial of service vulnerability exists when SymCrypt improperly handles a specially crafted digital signature2022-05-24

📋Vendor Advisories

1
Microsoft
SymCrypt Denial of Service Vulnerability2019-07-09

🕵️Threat Intelligence

3
Krebs
Patch Tuesday Lowdown, July 2019 Edition2019-07-13
Tenable
Microsoft’s July 2019 Patch Tuesday: What You Need to Know2019-07-09
Krebs
Patch Tuesday Lowdown, July 2019 Edition2019-07-09
CVE-2019-0865 — Microsoft Windows vulnerability | cvebase