Input validation error in Microsoft products - CVE-2019-1255

 

Input validation error in Microsoft products - CVE-2019-1255

Published: September 23, 2019


Vulnerability identifier: #VU21290
CSH Severity: Low
CVSS v4: 1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1255
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of files within the Microsoft Malware Protection Engine in Microsoft Defender. A remote attacker can create a specially crafted file, trick the victim into executing it and prevent legitimate accounts from executing legitimate system binaries. 


Affected software

Microsoft Security Essentials
Windows Defender
Microsoft Forefront Endpoint Protection

How to mitigate CVE-2019-1255

Install updates from vendor's website.
This vulnerability was addressed in Microsoft Malware Protection Engine 1.1.16400.2.


External References

Related Security Bulletins