Input validation error in Windows and Windows Server - CVE-2019-0688

 

Input validation error in Windows and Windows Server - CVE-2019-0688

Published: April 10, 2019


Vulnerability identifier: #VU18173
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-0688
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Microsoft
Affected software:
Windows
Windows Server

Detailed vulnerability description

The vulnerability allows a remote attacker to gain access so to sensitive information.

The vulnerability exists due to improper validation of fragmented IP packets within the Windows TCP/IP stack. A remote attacker can send specially crafted fragmented IP packets to the affected system and gain access to sensitive information, such as resource ids, sas tokens, user properties, etc.


How to mitigate CVE-2019-0688

Install updates from vendor's website.

Sources