Input validation error in Microsoft Windows and Windows Server - CVE-2019-0688

 

Input validation error in Microsoft Windows and Windows Server - CVE-2019-0688

Published: April 10, 2019


Vulnerability identifier: #VU18173
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0688
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access so to sensitive information.

The vulnerability exists due to improper validation of fragmented IP packets within the Windows TCP/IP stack. A remote attacker can send specially crafted fragmented IP packets to the affected system and gain access to sensitive information, such as resource ids, sas tokens, user properties, etc.


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2019-0688

Install updates from vendor's website.


External References

Related Security Bulletins