#VU18173 Input validation error in Windows and Windows Server - CVE-2019-0688
Published: April 10, 2019
Windows
Windows Server
Microsoft
Description
The vulnerability allows a remote attacker to gain access so to sensitive information.
The vulnerability exists due to improper validation of fragmented IP packets within the Windows TCP/IP stack. A remote attacker can send specially crafted fragmented IP packets to the affected system and gain access to sensitive information, such as resource ids, sas tokens, user properties, etc.