Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
CVE-2019-1337 — Sensitive Information Exposure in Microsoft Windows
Severity
5.5MEDIUMNVD
EPSS
0.9%
top 24.35%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedOct 10
Latest updateMay 24
Description
An information disclosure vulnerability exists when Windows Update Client fails to properly handle objects in memory, aka 'Windows Update Client Information Disclosure Vulnerability'.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6
Affected Packages7 packages
▶CVEListV5microsoft/windows10 Version 1809 for 32-bit Systems, 10 Version 1809 for ARM64-based Systems, 10 Version 1809 for x64-based Systems+2
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-x5vx-fhp4-xhcv: An information disclosure vulnerability exists when Windows Update Client fails to properly handle objects in memory, aka 'Windows Update Client Infor↗2022-05-24
CVEList▶
CVE-2019-1337: An information disclosure vulnerability exists when Windows Update Client fails to properly handle objects in memory, aka 'Windows Update Client Infor↗2019-10-10
💥Exploits & PoCs
6Exploit-DB
▶