⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.

CVE-2019-1224Sensitive Information Exposure in Microsoft Windows 10 Version 1803

Severity
7.5HIGHNVD
EPSS
5.0%
top 10.32%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedAug 14
Latest updateNov 30

Description

An information disclosure vulnerability exists when the Windows RDP server improperly discloses the contents of its memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the system. To exploit this vulnerability, an attacker would have to connect remotely to an affected system and run a specially crafted application. The security update addresses the vulnerability by correcting how the Windows RDP server initializes memory.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages25 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-4522-qq94-2q92: An information disclosure vulnerability exists when the Windows RDP server improperly discloses the contents of its memory, aka 'Remote Desktop Protoc2022-05-24
GHSA
GHSA-36vx-qm6w-f394: An information disclosure vulnerability exists when the Windows RDP server improperly discloses the contents of its memory, aka 'Remote Desktop Protoc2022-05-24
VulnCheck
Microsoft Windows Exposure of Sensitive Information to an Unauthorized Actor2019

📋Vendor Advisories

1
Microsoft
Remote Desktop Protocol Server Information Disclosure Vulnerability2019-08-13

🕵️Threat Intelligence

10
Sentinelone
Egregor2022-11-30
Qualys
August 2019 Patch Tuesday – 93 Vulns, 29 Critical, 7 Remote Desktop Vulns, Hyper-V, DHCP, Adobe vulns2019-08-13
Talos
Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage2019-08-13
Tenable
Tenable Roundup for Microsoft’s August 2019 Patch Tuesday: DejaBlue2019-08-13
Qualys
Windows Remote Desktop Vulnerabilities (Seven Monkeys) – How to Detect and Patch2019-08-13

💬Community

1
Bugzilla
CVE-2019-20800 cherokee: out-of-bounds write in cherokee_handler_cgi_add_env_pair function in handler_cgi.c2020-05-25
CVE-2019-1224 — Sensitive Information Exposure | cvebase