Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2019-1344Out-of-bounds Read in Microsoft Windows

CWE-125Out-of-bounds Read7 documents6 sources
Severity
5.5MEDIUMNVD
EPSS
5.5%
top 9.79%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedOct 10
Latest updateMay 24

Description

An information disclosure vulnerability exists in the way that the Windows Code Integrity Module handles objects in memory, aka 'Windows Code Integrity Module Information Disclosure Vulnerability'.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages7 packages

CVEListV5microsoft/windows20 versions+19
NVDmicrosoft/windowsr2, 1803, 1903+2
NVDmicrosoft/windows_106 versions+5
CVEListV5microsoft/windows_server17 versions+16

Patches

🔴Vulnerability Details

2
GHSA
GHSA-m55f-jfq4-f6r4: An information disclosure vulnerability exists in the way that the Windows Code Integrity Module handles objects in memory, aka 'Windows Code Integrit2022-05-24
CVEList
CVE-2019-1344: An information disclosure vulnerability exists in the way that the Windows Code Integrity Module handles objects in memory, aka 'Windows Code Integrit2019-10-10

💥Exploits & PoCs

1
Exploit-DB
Microsoft Windows Kernel - Out-of-Bounds Read in CI!CipFixImageType While Parsing Malformed PE File2019-10-10

📋Vendor Advisories

1
Microsoft
Windows Code Integrity Module Information Disclosure Vulnerability2019-10-08

🕵️Threat Intelligence

2
Talos
Microsoft Patch Tuesday — Oct. 2019: Vulnerability disclosures and Snort coverage2019-10-08
Talos
Microsoft Patch Tuesday — Oct. 2019: Vulnerability disclosures and Snort coverage2019-10-08
CVE-2019-1344 — Out-of-bounds Read in Microsoft Windows | cvebase