CVE-2019-1096Sensitive Information Exposure in Microsoft Windows

Severity
5.5MEDIUMNVD
EPSS
34.6%
top 2.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15
Latest updateMay 24

Description

An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages23 packages

CVEListV5microsoft/windows20 versions+19
NVDmicrosoft/windowsr2, 1803, 1903+2

Patches

🔴Vulnerability Details

1
GHSA
GHSA-vqhq-m79m-g645: An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vu2022-05-24

📋Vendor Advisories

1
Microsoft
Win32k Information Disclosure Vulnerability2019-07-09
CVE-2019-1096 — Sensitive Information Exposure | cvebase