⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.

CVE-2019-1108Sensitive Information Exposure in Microsoft Windows

Severity
6.5MEDIUMNVD
EPSS
23.5%
top 4.01%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJul 15
Latest updateNov 30

Description

An information disclosure vulnerability exists when the Windows RDP client improperly discloses the contents of its memory, aka 'Remote Desktop Protocol Client Information Disclosure Vulnerability'.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages24 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-c586-jcm8-hv2m: An information disclosure vulnerability exists when the Windows RDP client improperly discloses the contents of its memory, aka 'Remote Desktop Protoc2022-05-24
VulnCheck
Microsoft Windows Exposure of Sensitive Information to an Unauthorized Actor2019

📋Vendor Advisories

1
Microsoft
Remote Desktop Protocol Client Information Disclosure Vulnerability2019-07-09

🕵️Threat Intelligence

3
Sentinelone
Egregor2022-11-30
Sentinelone
Egregor
Zscaler
Zscaler found Multiple Security Vulnerabilities | 07-10-2019