CVE-2019-1292Static Code Injection in Microsoft Windows

Severity
4.9MEDIUMNVD
EPSS
3.5%
top 12.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 11
Latest updateMay 24

Description

A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 1.2 | Impact: 3.6

Affected Packages18 packages

CVEListV5microsoft/windows15 versions+14
NVDmicrosoft/windows1803, 1903+1
NVDmicrosoft/windows_106 versions+5
CVEListV5microsoft/windows_server5 versions+4

Patches

🔴Vulnerability Details

1
GHSA
GHSA-fqj2-3q62-4vw3: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'2022-05-24

📋Vendor Advisories

2
Microsoft
Windows Elevation of Privilege Vulnerability2019-09-10
Red Hat
jenkins-plugin-script-security: Sandbox Bypass in Script Security Plugin (SECURITY-1292)2019-01-29

💬Community

1
Bugzilla
CVE-2019-1003005 jenkins-plugin-script-security: Sandbox Bypass in Script Security Plugin (SECURITY-1292)2019-01-29
CVE-2019-1292 — Static Code Injection in Microsoft | cvebase