Security Features in Microsoft Windows and Windows Server - CVE-2019-1488
Published: December 10, 2019
Vulnerability identifier: #VU23504
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1488
CWE-ID: CWE-254
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to bypass security features on the target system.
The vulnerability exists due to the Microsoft Defender improperly handles specific buffers. A local user can trigger warnings and false positives when no threat is present.
To exploit the vulnerability, an attacker would first require execution permissions on the victim system.Affected software
Microsoft Windows
Windows Server
Windows Server
How to mitigate CVE-2019-1488
Install updates from vendor's website.