#VU21690 Permissions, Privileges, and Access Controls in Windows and Windows Server - CVE-2019-1368
Published: October 9, 2019
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local attacker to gain access to sensitive information.
The vulnerability exists due incorrect restrictions for the debugging functionality in Windows Secure Boot. A local attacker with physical access to the system can disclose kernel memory.
Successful exploitation of the vulnerability requires that Windows Secure Boot is enabled.