CVE-2019-1318Authentication Bypass by Spoofing in Microsoft Windows

Severity
5.9MEDIUMNVD
EPSS
2.8%
top 13.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 10
Latest updateMay 24

Description

A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions, aka 'Microsoft Windows Transport Layer Security Spoofing Vulnerability'.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages7 packages

CVEListV5microsoft/windows20 versions+19
NVDmicrosoft/windowsr2, 1803, 1903+2
NVDmicrosoft/windows_106 versions+5
CVEListV5microsoft/windows_server17 versions+16

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2v8j-7w32-jrwf: A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions, aka 'Microsoft Windows Transp2022-05-24
CVEList
CVE-2019-1318: A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions, aka 'Microsoft Windows Transp2019-10-10

📋Vendor Advisories

1
Microsoft
Microsoft Windows Transport Layer Security Spoofing Vulnerability2019-10-08

🕵️Threat Intelligence

2
Talos
Microsoft Patch Tuesday — Oct. 2019: Vulnerability disclosures and Snort coverage2019-10-08
Talos
Microsoft Patch Tuesday — Oct. 2019: Vulnerability disclosures and Snort coverage2019-10-08
CVE-2019-1318 — Authentication Bypass by Spoofing | cvebase