CVE-2019-1091Sensitive Information Exposure in Microsoft Windows

Severity
5.5MEDIUMNVD
EPSS
1.2%
top 21.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15
Latest updateMay 24

Description

An information disclosure vulnerability exists when Unistore.dll fails to properly handle objects in memory, aka 'Microsoft unistore.dll Information Disclosure Vulnerability'.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages18 packages

CVEListV5microsoft/windows15 versions+14
NVDmicrosoft/windows1803, 1903+1
NVDmicrosoft/windows_106 versions+5
CVEListV5microsoft/windows_server5 versions+4

Patches

🔴Vulnerability Details

1
GHSA
GHSA-843c-r5h3-9m54: An information disclosure vulnerability exists when Unistore2022-05-24

📋Vendor Advisories

1
Microsoft
Microsoft unistore.dll Information Disclosure Vulnerability2019-07-09

💬Community

1
Bugzilla
CVE-2019-12387 python-twisted: Improper neutralization of CRLF characters in URIs and HTTP methods2019-06-12
CVE-2019-1091 — Sensitive Information Exposure | cvebase