CVE-2019-1178
published 2019-08-14CVE-2019-1178: An elevation of privilege vulnerability exists in the way that the ssdpsrv.dll handles objects in memory. An attacker who successfully exploited the…
PriorityP430high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.82%
53.0th percentile
An elevation of privilege vulnerability exists in the way that the ssdpsrv.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update addresses the vulnerability by ensuring the ssdpsrv.dll properly handles objects in memory.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1607 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1703 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1709 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1709_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1803 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_arm64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_x64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_7 | >= 6.1.0 < publication | publication |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < publication | publication |
| microsoft | windows_8.1 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.0.0 < publication | publication |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.0 < publication | publication |
| microsoft | windows_server_2008_r2_systems_service_pack_1 | >= 6.1.0 < publication | publication |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.0 < publication | publication |
| microsoft | windows_server_2012 | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_msrc7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5xj6-qhjx-f6xh: An elevation of privilege vulnerability exists in the way that the wcmsvc
ghsa_unreviewed·2022-05-24·CVSS 7.0
CVE-2019-1180 [HIGH] GHSA-5xj6-qhjx-f6xh: An elevation of privilege vulnerability exists in the way that the wcmsvc
An elevation of privilege vulnerability exists in the way that the wcmsvc.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1173, CVE-2019-1174, CVE-2019-1175, CVE-2019-1177, CVE-2019-1178, CVE-2019-1179, CVE-2019-1184, CVE-2019-1186.
GHSA
GHSA-82mq-2jww-m58g: An elevation of privilege vulnerability exists in the way that the unistore
ghsa_unreviewed·2022-05-24·CVSS 7.0
CVE-2019-1179 [HIGH] GHSA-82mq-2jww-m58g: An elevation of privilege vulnerability exists in the way that the unistore
An elevation of privilege vulnerability exists in the way that the unistore.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1173, CVE-2019-1174, CVE-2019-1175, CVE-2019-1177, CVE-2019-1178, CVE-2019-1180, CVE-2019-1184, CVE-2019-1186.
GHSA
GHSA-f245-h455-7hqv: An elevation of privilege vulnerability exists in the way that the PsmServiceExtHost
ghsa_unreviewed·2022-05-24·CVSS 7.0
CVE-2019-1173 [HIGH] GHSA-f245-h455-7hqv: An elevation of privilege vulnerability exists in the way that the PsmServiceExtHost
An elevation of privilege vulnerability exists in the way that the PsmServiceExtHost.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1174, CVE-2019-1175, CVE-2019-1177, CVE-2019-1178, CVE-2019-1179, CVE-2019-1180, CVE-2019-1184, CVE-2019-1186.
GHSA
GHSA-vfjm-94qj-mfgw: An elevation of privilege vulnerability exists in the way that the ssdpsrv
ghsa_unreviewed·2022-05-24·CVSS 7.0
CVE-2019-1178 [HIGH] GHSA-vfjm-94qj-mfgw: An elevation of privilege vulnerability exists in the way that the ssdpsrv
An elevation of privilege vulnerability exists in the way that the ssdpsrv.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1173, CVE-2019-1174, CVE-2019-1175, CVE-2019-1177, CVE-2019-1179, CVE-2019-1180, CVE-2019-1184, CVE-2019-1186.
GHSA
GHSA-5fw3-2234-g822: An elevation of privilege vulnerability exists in the way that the psmsrv
ghsa_unreviewed·2022-05-24·CVSS 7.0
CVE-2019-1175 [HIGH] CWE-269 GHSA-5fw3-2234-g822: An elevation of privilege vulnerability exists in the way that the psmsrv
An elevation of privilege vulnerability exists in the way that the psmsrv.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1173, CVE-2019-1174, CVE-2019-1177, CVE-2019-1178, CVE-2019-1179, CVE-2019-1180, CVE-2019-1184, CVE-2019-1186.
GHSA
GHSA-xr5g-7pxf-gp8f: An elevation of privilege vulnerability exists in the way that the rpcss
ghsa_unreviewed·2022-05-24·CVSS 7.0
CVE-2019-1177 [HIGH] CWE-269 GHSA-xr5g-7pxf-gp8f: An elevation of privilege vulnerability exists in the way that the rpcss
An elevation of privilege vulnerability exists in the way that the rpcss.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1173, CVE-2019-1174, CVE-2019-1175, CVE-2019-1178, CVE-2019-1179, CVE-2019-1180, CVE-2019-1184, CVE-2019-1186.
GHSA
GHSA-hxfv-8253-2p76: An elevation of privilege vulnerability exists in the way that the wcmsvc
ghsa_unreviewed·2022-05-24·CVSS 7.0
CVE-2019-1186 [HIGH] GHSA-hxfv-8253-2p76: An elevation of privilege vulnerability exists in the way that the wcmsvc
An elevation of privilege vulnerability exists in the way that the wcmsvc.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1173, CVE-2019-1174, CVE-2019-1175, CVE-2019-1177, CVE-2019-1178, CVE-2019-1179, CVE-2019-1180, CVE-2019-1184.
GHSA
GHSA-24jg-p7g4-p8rm: An elevation of privilege vulnerability exists when Windows Core Shell COM Server Registrar improperly handles COM calls, aka 'Windows Elevation of Pr
ghsa_unreviewed·2022-05-24·CVSS 7.0
CVE-2019-1184 [HIGH] GHSA-24jg-p7g4-p8rm: An elevation of privilege vulnerability exists when Windows Core Shell COM Server Registrar improperly handles COM calls, aka 'Windows Elevation of Pr
An elevation of privilege vulnerability exists when Windows Core Shell COM Server Registrar improperly handles COM calls, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1173, CVE-2019-1174, CVE-2019-1175, CVE-2019-1177, CVE-2019-1178, CVE-2019-1179, CVE-2019-1180, CVE-2019-1186.
GHSA
GHSA-9qcm-3p54-9cgq: An elevation of privilege vulnerability exists in the way that the PsmServiceExtHost
ghsa_unreviewed·2022-05-24·CVSS 7.0
CVE-2019-1174 [HIGH] CWE-1257 GHSA-9qcm-3p54-9cgq: An elevation of privilege vulnerability exists in the way that the PsmServiceExtHost
An elevation of privilege vulnerability exists in the way that the PsmServiceExtHost.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1173, CVE-2019-1175, CVE-2019-1177, CVE-2019-1178, CVE-2019-1179, CVE-2019-1180, CVE-2019-1184, CVE-2019-1186.
Microsoft
Windows Elevation of Privilege Vulnerability
vendor_msrc·2019-08-13·CVSS 7.0
CVE-2019-1178 [HIGH] Windows Elevation of Privilege Vulnerability
Windows Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in the way that the ssdpsrv.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update addresses the vulnerability by ensuring the ssdpsrv.dll properly handles objects in memory.
Microsoft Windows: Microsoft Windows
Microsoft: Microsoft
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.a
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
blogs_talos·2019-08-13·CVSS 9.1
[CRITICAL] Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
Microsoft released its monthly security update today, disclosing a variety of vulnerabilities in several of its products. The latest Patch Tuesday covers 97 vulnerabilities, 31 of which are rated “critical," 65 that are considered "important" and one "moderate."
This month’s security update covers security issues in a variety of Microsoft services and software, including certain graphics components, Outlook and the Chakra Scripting Engine. For more on our coverage of these bugs, check out our Snort advisories here, covering all of the new rules we have for this release.
### Critical vulnerabilities Microsoft disclosed 31 critical vulnerabilities this month, three of which we will highlight below.
CVE-2019-1181 and CVE-2019-1182 are both remote code execution vulnerabilities in Remote De
Talos
Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
blogs_talos·2019-08-13·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
## Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
Microsoft released its monthly security update today, disclosing a variety of vulnerabilities in several of its products. The latest Patch Tuesday covers 97 vulnerabilities, 31 of which are rated “critical," 65 that are considered "important" and one "moderate."
This month’s security update covers security issues in a variety of Microsoft services and software, including certain graphics components, Outlook and the Chakra Scripting Engine. For more on our coverage of these bugs, check out our Snort advisories here , covering all of the new rules we have for this release.
## Critical vulnerabilities Microsoft disclosed 31 critical vulnerabilities this month, three of which we will highlight below.
CVE-2
Bugzilla
CVE-2019-19648 yara: out-of-bounds memory access in macho_parse_file in macho/macho.c
bugzilla·2019-12-13·CVSS 7.8
CVE-2019-19648 [HIGH] CVE-2019-19648 yara: out-of-bounds memory access in macho_parse_file in macho/macho.c
CVE-2019-19648 yara: out-of-bounds memory access in macho_parse_file in macho/macho.c
In the macho_parse_file functionality in macho/macho.c of YARA 3.11.0, command_size may be inconsistent with the real size. A specially crafted MachO file can cause an out-of-bounds memory access, resulting in Denial of Service (application crash) or potential code execution.
Reference:
https://github.com/VirusTotal/yara/issues/1178
Discussion:
Created yara tracking bugs for this issue:
Affects: epel-all [bug 1783442]
Affects: fedora-all [bug 1783440]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
Bugzilla
CVE-2019-6988 openjpeg: DoS via memory exhaustion in opj_decompress
bugzilla·2019-01-30·CVSS 6.5
CVE-2019-6988 [MEDIUM] CVE-2019-6988 openjpeg: DoS via memory exhaustion in opj_decompress
CVE-2019-6988 openjpeg: DoS via memory exhaustion in opj_decompress
An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a
denial of service (attempted excessive memory allocation) in opj_calloc in
openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as
demonstrated by the 64-bit opj_decompress.
References:
https://github.com/uclouvain/openjpeg/issues/1178
Discussion:
Created openjpeg tracking bugs for this issue:
Affects: fedora-all [bug 1670983]
---
Analysis:
This is essentially a memory exhaustion flaw in the way, the decompressor allocates memory, caused by specially-crafted JPEG2000 file headers. The only impact of this flaw is machine hang, depending on the amount of memory available on the system.
2019-08-14
Published