CVE-2019-1220

Severity
4.3MEDIUM
EPSS
5.9%
top 9.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 11
Latest updateMay 24

Description

A security feature bypass vulnerability exists when Microsoft Browsers fail to validate the correct Security Zone of requests for specific URLs, aka 'Microsoft Browser Security Feature Bypass Vulnerability'.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages28 packages

CVEListV5microsoft/internet_explorer_9Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for x64-based Systems Service Pack 2+1
CVEListV5microsoft/internet_explorer_10Windows Server 2012
CVEListV5microsoft/internet_explorer_1124 versions+23

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8c6c-962w-cq52: A security feature bypass vulnerability exists when Microsoft Browsers fail to validate the correct Security Zone of requests for specific URLs, aka '2022-05-24
CVEList
CVE-2019-1220: A security feature bypass vulnerability exists when Microsoft Browsers fail to validate the correct Security Zone of requests for specific URLs, aka '2019-09-11

📋Vendor Advisories

3
Red Hat
hw: Intel SGX information leak2019-11-12
Microsoft
Microsoft Browser Security Feature Bypass Vulnerability2019-09-10
Red Hat
containerized-data-importer: Exposed read access to all storage currently allocated to PVCs regardless of namespace2019-06-01
CVE-2019-1220 (MEDIUM CVSS 4.3) | A security feature bypass vulnerabi | cvebase.io