Insufficient verification of data authenticity in Microsoft Windows and Windows Server - CVE-2019-1235

 

Insufficient verification of data authenticity in Microsoft Windows and Windows Server - CVE-2019-1235

Published: September 10, 2019


Vulnerability identifier: #VU21009
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1235
CWE-ID: CWE-345
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due insufficient validation of input data origin within the Windows Text Service Framework (TSF) server, sent through a malicious Input Method Editor (IME). A local user can run a specially crafted application and escalate privileges on the system.

Successful exploitation of the vulnerability requires that IME is installed on the system.


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2019-1235

Install updates from vendor's website.


External References

Related Security Bulletins