Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2019-1337Sensitive Information Exposure in Microsoft Windows

Severity
5.5MEDIUMNVD
EPSS
0.9%
top 24.35%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedOct 10
Latest updateMay 24

Description

An information disclosure vulnerability exists when Windows Update Client fails to properly handle objects in memory, aka 'Windows Update Client Information Disclosure Vulnerability'.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages7 packages

CVEListV5microsoft/windows10 Version 1809 for 32-bit Systems, 10 Version 1809 for ARM64-based Systems, 10 Version 1809 for x64-based Systems+2
NVDmicrosoft/windows_101809, 1903+1
CVEListV5microsoft/windows_server2019, 2019 (Core installation)+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x5vx-fhp4-xhcv: An information disclosure vulnerability exists when Windows Update Client fails to properly handle objects in memory, aka 'Windows Update Client Infor2022-05-24
CVEList
CVE-2019-1337: An information disclosure vulnerability exists when Windows Update Client fails to properly handle objects in memory, aka 'Windows Update Client Infor2019-10-10

💥Exploits & PoCs

6
Exploit-DB
Netis WF2419 2.2.36123 - Remote Code Execution2020-03-02
Exploit-DB
Cisco Data Center Network Manager 11.2.1 - 'getVmHostData' SQL Injection2020-02-06
Exploit-DB
Cisco Data Center Network Manager 11.2.1 - 'LanFabricImpl' Command Injection2020-02-06
Exploit-DB
Cisco Data Center Network Manager 11.2 - Remote Code Execution2020-02-06
Exploit-DB
JavaScriptCore - Type Confusion During Bailout when Reconstructing Arguments Objects2019-11-05

📋Vendor Advisories

1
Microsoft
Windows Update Client Information Disclosure Vulnerability2019-10-08

🕵️Threat Intelligence

2
Talos
Microsoft Patch Tuesday — Oct. 2019: Vulnerability disclosures and Snort coverage2019-10-08
Talos
Microsoft Patch Tuesday — Oct. 2019: Vulnerability disclosures and Snort coverage2019-10-08
CVE-2019-1337 — Sensitive Information Exposure | cvebase