Input validation error in Microsoft Windows and Windows Server - CVE-2019-0688
Published: April 10, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain access so to sensitive information.
The vulnerability exists due to improper validation of fragmented IP packets within the Windows TCP/IP stack. A remote attacker can send specially crafted fragmented IP packets to the affected system and gain access to sensitive information, such as resource ids, sas tokens, user properties, etc.
Affected software
Windows Server