CVE-2019-1044
published 2019-06-12CVE-2019-1044: A security feature bypass vulnerability exists when Windows Secure Kernel Mode fails to properly handle objects in memory. To exploit the vulnerability, a…
PriorityP424medium5.3CVSS 3.1
AVLACLPRLUINSUCLILAL
EPSS
1.01%
59.3th percentile
A security feature bypass vulnerability exists when Windows Secure Kernel Mode fails to properly handle objects in memory.
To exploit the vulnerability, a locally-authenticated attacker could attempt to run a specially crafted application on a targeted system. An attacker who successfully exploited the vulnerability could violate virtual trust levels (VTL).
The update addresses the vulnerability by correcting how Windows Secure Kernel Mode handles objects in memory to properly enforce VTLs.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1809 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < publication | publication |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < publication | publication |
| msrc | windows_10_version_1809_for_32-bit_systems | — | — |
| msrc | windows_10_version_1809_for_arm64-based_systems | — | — |
| msrc | windows_10_version_1809_for_x64-based_systems | — | — |
| msrc | windows_server_2019 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7q9v-9pcr-vqfv: A security feature bypass vulnerability exists when Windows Secure Kernel Mode fails to properly handle objects in memory
ghsa_unreviewed·2022-05-24
CVE-2019-1044 [HIGH] GHSA-7q9v-9pcr-vqfv: A security feature bypass vulnerability exists when Windows Secure Kernel Mode fails to properly handle objects in memory
A security feature bypass vulnerability exists when Windows Secure Kernel Mode fails to properly handle objects in memory.To exploit the vulnerability, a locally-authenticated attacker could attempt to run a specially crafted application on a targeted system, aka 'Windows Secure Kernel Mode Security Feature Bypass Vulnerability'.
Microsoft
Windows Secure Kernel Mode Security Feature Bypass Vulnerability
vendor_msrc·2019-06-11·CVSS 5.3
CVE-2019-1044 [MEDIUM] Windows Secure Kernel Mode Security Feature Bypass Vulnerability
Windows Secure Kernel Mode Security Feature Bypass Vulnerability
Description: A security feature bypass vulnerability exists when Windows Secure Kernel Mode fails to properly handle objects in memory.
To exploit the vulnerability, a locally-authenticated attacker could attempt to run a specially crafted application on a targeted system. An attacker who successfully exploited the vulnerability could violate virtual trust levels (VTL).
The update addresses the vulnerability by correcting how Windows Secure Kernel Mode handles objects in memory to properly enforce VTLs.
Windows Kernel: Windows Kernel
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A;Older Software Release:Expl
No detection rules found.
No public exploits indexed.
2019-06-12
Published