CVE-2019-1416Race Condition in Microsoft Windows

CWE-362Race Condition8 documents6 sources
Severity
7.0HIGHNVD
EPSS
0.2%
top 55.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12
Latest updateMay 24

Description

An elevation of privilege vulnerability exists due to a race condition in Windows Subsystem for Linux, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages7 packages

CVEListV5microsoft/windows9 versions+8
NVDmicrosoft/windows1803, 1903+1
NVDmicrosoft/windows_104 versions+3
CVEListV5microsoft/windows_server2019, 2019 (Core installation), version 1803 (Core Installation)+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mfcw-9c9c-27wj: An elevation of privilege vulnerability exists due to a race condition in Windows Subsystem for Linux, aka 'Windows Subsystem for Linux Elevation of P2022-05-24
CVEList
CVE-2019-1416: An elevation of privilege vulnerability exists due to a race condition in Windows Subsystem for Linux, aka 'Windows Subsystem for Linux Elevation of P2019-11-12

📋Vendor Advisories

1
Microsoft
Windows Subsystem for Linux Elevation of Privilege Vulnerability2019-11-12

🕵️Threat Intelligence

2
Talos
Microsoft Patch Tuesday — Nov. 2019: Vulnerability disclosures and Snort coverage2019-11-12
Talos
Microsoft Patch Tuesday — Nov. 2019: Vulnerability disclosures and Snort coverage2019-11-12

💬Community

2
Bugzilla
CVE-2019-15225 envoy: crafted request with long URI allows remote attacker to cause denial of service2019-10-25
Bugzilla
CVE-2019-14993 istio/envoy: mishandling regular expressions for long URIs leading to DoS2019-10-09
CVE-2019-1416 — Race Condition in Microsoft Windows | cvebase