#VU18173 Input validation error in Windows and Windows Server - CVE-2019-0688

 

#VU18173 Input validation error in Windows and Windows Server - CVE-2019-0688

Published: April 10, 2019


Vulnerability identifier: #VU18173
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-0688
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Windows
Windows Server
Software vendor:
Microsoft

Description

The vulnerability allows a remote attacker to gain access so to sensitive information.

The vulnerability exists due to improper validation of fragmented IP packets within the Windows TCP/IP stack. A remote attacker can send specially crafted fragmented IP packets to the affected system and gain access to sensitive information, such as resource ids, sas tokens, user properties, etc.


Remediation

Install updates from vendor's website.

External links