CVE-2019-1019
published 2019-06-12CVE-2019-1019: A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages. To exploit this vulnerability, an…
PriorityP267high8.5CVSS 3.1
AVNACHPRLUINSCCHIHAH
EXPLOIT
EPSS
15.12%
96.4th percentile
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.
To exploit this vulnerability, an attacker could send a specially crafted authentication request. An attacker who successfully exploited this vulnerability could access another machine using the original user privileges.
The issue has been addressed by changing how NTLM validates network authentication messages.
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < publication | publication |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < publication | publication |
| microsoft | windows_10_version_1703 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1709 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1709_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1803 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < publication | publication |
| microsoft | windows_10_version_1903_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_arm64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_x64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_7 | >= 6.1.0 < publication | publication |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < publication | publication |
| microsoft | windows_8.1 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < publication | publication |
| microsoft | windows_server_2008_r2_systems_service_pack_1 | >= 6.1.0 < publication | publication |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.0 < publication | publication |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < publication | publication |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect NTLM relay attack: monitor for NTLM_CHALLENGE messages where the hostname/Target Info field has been stripped (no hostname present), followed by a NETLOGON session key request to a DC — this is the core CVE-2019-1019 exploitation pattern. ↗
- →Detect NETLOGON requests to a DC where the target hostname field is absent — this is the condition that allows the session key to be retrieved by the relayer. ↗
- →Detect clearing of the NTLMSSP_NEGOTIATE_OEM_DOMAIN_SUPPLIED flag in NTLM NEGOTIATE_MESSAGE packets — this is used by the attacker to force remote-mode authentication and enable HTTP→SMB NTLM reflection. ↗
- →Detect EfsRpcOpenFileRaw calls using UNC paths of the form \\localhost\C$\... or paths starting with \\.\ — these are path-check bypass techniques used in the exploit chain. ↗
- →Monitor for new executable files appearing in the current user's Startup folder, especially those dropped via EFSRPC copy operations — this is the payload delivery mechanism in the PoC. ↗
- →Monitor for MSRPC calls to the EFSRPC endpoint UUID c681d488-d850-11d0-8c52-00c04fd90f7e on the lsass named pipe, which may be used as an alternative to the efsrpc named pipe in exploitation. ↗
- →Alert on RELAYER establishing a signed SMB/LDAP session against a target after performing NTLM relay — indicates successful exploitation of CVE-2019-1019 where MIC was forged using the retrieved session key. ↗
- ·SMB signing is not enforced by default on non-DC workstations, making environments without explicit SMB signing policy vulnerable to simpler NTLM relay attacks that do not require the CVE-2019-1019 session key retrieval technique. ↗
- ·LDAP signing and LDAP channel binding are disabled by default on domain controllers, leaving them exposed to NTLM relay attacks even after patching CVE-2019-1019 if these settings are not explicitly enabled. ↗
- ·The efsrpc named pipe may not be enabled by default, but the same vulnerable EFSRPC RPC endpoint (UUID c681d488-d850-11d0-8c52-00c04fd90f7e) is accessible via the lsass named pipe, so disabling efsrpc alone is insufficient mitigation. ↗
- ·All Windows versions that have not applied the June 2019 Patch Tuesday update are vulnerable, including those supporting Windows Integrated Authentication (WIA) services such as Exchange and ADFS. ↗
CVSS provenance
nvdv3.18.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv3.08.5HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
vendor_msrc8.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Windows Security Feature Bypass Vulnerability
vendor_msrc·2019-06-11·CVSS 8.5
CVE-2019-1019 [HIGH] Microsoft Windows Security Feature Bypass Vulnerability
Microsoft Windows Security Feature Bypass Vulnerability
Description: A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.
To exploit this vulnerability, an attacker could send a specially crafted authentication request. An attacker who successfully exploited this vulnerability could access another machine using the original user privileges.
The issue has been addressed by changing how NTLM validates network authentication messages.
Windows NTLM: Windows NTLM
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://
GHSA
GHSA-5fqm-f4f4-5vpq: A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages
ghsa_unreviewed·2022-05-24
CVE-2019-1019 [HIGH] CWE-200 GHSA-5fqm-f4f4-5vpq: A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an attacker could send a specially crafted authentication request, aka 'Microsoft Windows Security Feature Bypass Vulnerability'.
No detection rules found.
Tenable
Tenable Roundup for Microsoft's June 2019 Patch Tuesday
blogs_tenable·2019-06-11
Tenable Roundup for Microsoft's June 2019 Patch Tuesday
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Crowdstrike
What is a Zero-Day Exploit?
blogs_crowdstrike·CVSS 9.8
[CRITICAL] What is a Zero-Day Exploit?
Upcoming events
Conference
CrowdTour
Find a city near you
Your Cart
Added to Cart
There's nothing in your cart
per endpoint / per year
per endpoint / per month
Login
Login
Experienced a breach?
Contact us
## "Zero-Day" Definition
The term "Zero-Day" is used when security teams are unaware of their software vulnerability, and they’ve had “0” days to work on a security patch or an update to fix the issue. “Zero-Day” is commonly associated with the terms Vulnerability , Exploit , and Threat . It is important to understand the difference:
A Zero-Day Vulnerability is an unknown security vulnerability or software flaw that a threat actor can target with malicious code.
A Zero-Day Exploit is the technique or tactic a malicious actor uses to leverage the vulnerability to attack a
Crowdstrike
How to Retrieve the Session Key for Any Authentication
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] How to Retrieve the Session Key for Any Authentication
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
What is a Zero-Day Exploit?
blogs_crowdstrike
What is a Zero-Day Exploit?
Upcoming events
Conference
CrowdTour
Find a city near you
Summit
Day Zero 2026
Las Vegas, NV
Login
Your Cart
Added to Cart
There's nothing in your cart
per endpoint / per year
per endpoint / per month
Login
Experienced a breach?
Blog
Contact us
Careers
Latest Innovations
## "Zero-Day" Definition
The term "Zero-Day" is used when security teams are unaware of their software vulnerability, and they’ve had “0” days to work on a security patch or an update to fix the issue. “Zero-Day” is commonly associated with the terms Vulnerability , Exploit , and Threat . It is important to understand the difference:
A Zero-Day Vulnerability is an unknown security vulnerability or software flaw that a threat actor can target with malicious code.
A Zero-Day Exploit is the technique o
Crowdstrike
How to Retrieve the Session Key for Any Authentication
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] How to Retrieve the Session Key for Any Authentication
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Crowdstrike
What is a Zero-Day Exploit?
blogs_crowdstrike·CVSS 9.8
[CRITICAL] What is a Zero-Day Exploit?
Upcoming events
Conference
CrowdTour
Find a city near you
Login
Your Cart
Added to Cart
There's nothing in your cart
per endpoint / per year
per endpoint / per month
Login
Experienced a breach?
Contact us
## "Zero-Day" Definition
The term "Zero-Day" is used when security teams are unaware of their software vulnerability, and they’ve had “0” days to work on a security patch or an update to fix the issue. “Zero-Day” is commonly associated with the terms Vulnerability , Exploit , and Threat . It is important to understand the difference:
A Zero-Day Vulnerability is an unknown security vulnerability or software flaw that a threat actor can target with malicious code.
A Zero-Day Exploit is the technique or tactic a malicious actor uses to leverage the vulnerability to attack a
Bugzilla
CVE-2019-18838 envoy: malformed HTTP request without the Host header may cause abnormal termination of the Envoy process
bugzilla·2019-11-18·CVSS 7.5
CVE-2019-18838 [HIGH] CVE-2019-18838 envoy: malformed HTTP request without the Host header may cause abnormal termination of the Envoy process
CVE-2019-18838 envoy: malformed HTTP request without the Host header may cause abnormal termination of the Envoy process
Malformed HTTP request without the Host header may cause abnormal termination of the Envoy process
Discussion:
Note the alias for this issue is CVE-1019-18838 but should be CVE-2019-18838, I've updated the summary but there appears to be something else to be updated by the security team. Tim added the same comment on 25th November.
---
External References:
https://groups.google.com/forum/#!topic/envoy-users/m7z5fGkCzPI
https://github.com/envoyproxy/envoy/security/advisories/GHSA-f2rv-4w6x-rwhc
---
This issue has been addressed in the following products:
Openshift Service Mesh 1.0
OpenShift Service Mesh 1.0
Via RHSA-2019:4222 https://access.redhat.com/errata/RHS
Bugzilla
CVE-2019-17402 exiv2: out-of-bounds read in CiffDirectory::readDirectory due to lack of size check
bugzilla·2019-11-18·CVSS 6.5
CVE-2019-17402 [MEDIUM] CVE-2019-17402 exiv2: out-of-bounds read in CiffDirectory::readDirectory due to lack of size check
CVE-2019-17402 exiv2: out-of-bounds read in CiffDirectory::readDirectory due to lack of size check
Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of the relationship of the total size to the offset and size.
Reference:
https://github.com/Exiv2/exiv2/issues/1019
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1773684]
---
Upstream patch:
https://github.com/Exiv2/exiv2/commit/88054239e3c914862d13f6ac89a19a104fa2c076 [master branch]
https://github.com/Exiv2/exiv2/commit/50e9dd964a439da357798344ed1dd86edcadf0ec [0.27-maintanance branch]
Opened upstream issue to discuss improving the fix:
https://github.com/
2019-06-12
Published