Information disclosure in Microsoft Windows and Windows Server - CVE-2019-1125

 

Information disclosure in Microsoft Windows and Windows Server - CVE-2019-1125

Published: August 6, 2019 / Updated: June 17, 2021


Vulnerability identifier: #VU19946
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1125
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information and elevate privileges on the system.

The vulnerability exists when certain central processing units (CPU) speculatively access memory. A local user can gain unauthorized access to sensitive information and elevate privileges on the system.

This issue is a variant of the Spectre Variant 1 speculative execution side channel vulnerability that leverages SWAPGS instructions to bypass KPTI/KVA mitigations.


Affected software

Microsoft Windows
Windows Server
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Virtualization Host - Extended Update Support 4.2 for RHEL
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Slackware Linux
Opensuse
Fedora

MRG Realtime
F5 iWorkflow
BIG-IQ Centralized Management
kernel (Red Hat package)
kernel-rt (Red Hat package)
linux-aws-hwe (Ubuntu package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
linux-aws (Ubuntu package)
kernel-tools
kernel-headers
kernel
Enterprise Manager
Red Hat Virtualization Host
Red Hat Virtualization
Traffix SDC
BIG-IP LTM
Data Computing Appliance (DCA)
SmartFabric OS10
SCALANCE M812-1 ADSL-Router (Annex A)
RUGGEDCOM RM1224 LTE(4G) EU
RUGGEDCOM RM1224 LTE(4G) NAM
SCALANCE S615 EEC
SCALANCE MUM856-1 (RoW)
SCALANCE MUM856-1 (EU)
SCALANCE MUM853-1 (EU)
SCALANCE M876-4 (NAM)
SCALANCE M876-4 (EU)
SCALANCE M876-4
SCALANCE M876-3 (ROK)
SCALANCE M876-3 (EVDO)
SCALANCE M874-3
SCALANCE M874-2
SCALANCE M826-2 SHDSL-Router
SCALANCE M816-1 ADSL-Router (Annex B)
SCALANCE M816-1 ADSL-Router (Annex A)
SCALANCE M812-1 ADSL-Router (Annex B)
SCALANCE M804PB
SCALANCE S615

How to mitigate CVE-2019-1125

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

kernel (Red Hat package) - addressed in versions 2.6.32-431.96.1.el6, 2.6.32-504.80.2.el6, 2.6.32-754.18.2.el6, 3.10.0-327.82.1.el7, 3.10.0-514.69.1.el7, 3.10.0-693.58.1.el7, 3.10.0-862.43.1.el7, 3.10.0-957.38.1.el7, 3.10.0-1062.1.1.el7, 4.18.0-80.7.2.el8_0
kernel-rt (Red Hat package) - addressed in versions 3.10.0-693.58.1.rt56.652.el6rt, 3.10.0-1062.1.1.rt56.1024.el7, 4.18.0-80.7.2.rt9.154.el8_0
linux-aws-hwe (Ubuntu package) - update to 4.15.0-1045.47~16.04.1
Data Computing Appliance (DCA) - update to 3.5.4.0
linux-aws (Ubuntu package) - addressed in versions 4.15.0-1045.47, 5.0.0-1012.13
kernel-tools - addressed in versions 5.2.7-100.fc29, 5.2.7-200.fc30
kernel-headers - addressed in versions 5.2.7-100.fc29, 5.2.7-200.fc30
kernel - addressed in versions 5.2.7-100.fc29, 5.2.7-200.fc30
SCALANCE M812-1 ADSL-Router (Annex A) - update to 7.2
RUGGEDCOM RM1224 LTE(4G) EU - update to 7.2
RUGGEDCOM RM1224 LTE(4G) NAM - update to 7.2
SCALANCE S615 EEC - update to 7.2
SCALANCE S615 - update to 7.2
SCALANCE MUM856-1 (RoW) - update to 7.2
SCALANCE MUM856-1 (EU) - update to 7.2
SCALANCE MUM853-1 (EU) - update to 7.2
SCALANCE M876-4 (NAM) - update to 7.2
SCALANCE M876-4 (EU) - update to 7.2
SCALANCE M876-4 - update to 7.2
SCALANCE M876-3 (ROK) - update to 7.2
SCALANCE M876-3 (EVDO) - update to 7.2
SCALANCE M874-3 - update to 7.2
SCALANCE M874-2 - update to 7.2
SCALANCE M826-2 SHDSL-Router - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M804PB - update to 7.2
SmartFabric OS10 - update to 10.5.0.3

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins