SB2019041003 - Information disclosure in Windows TCP/IP stack implementation
Published: April 10, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2019-0688)
The vulnerability allows a remote attacker to gain access so to sensitive information.
The vulnerability exists due to improper validation of fragmented IP packets within the Windows TCP/IP stack. A remote attacker can send specially crafted fragmented IP packets to the affected system and gain access to sensitive information, such as resource ids, sas tokens, user properties, etc.
Remediation
Install update from vendor's website.