CVE-2019-1318 — Authentication Bypass by Spoofing in Microsoft Windows
Severity
5.9MEDIUMNVD
EPSS
2.8%
top 13.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 10
Latest updateMay 24
Description
A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions, aka 'Microsoft Windows Transport Layer Security Spoofing Vulnerability'.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6
Affected Packages7 packages
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-2v8j-7w32-jrwf: A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions, aka 'Microsoft Windows Transp↗2022-05-24
CVEList▶
CVE-2019-1318: A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions, aka 'Microsoft Windows Transp↗2019-10-10