CVE-2019-0683

Description

An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka Active Directory Elevation of Privilege Vulnerability.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
4.281

Associated Vulnerability

VulnerabilityOS Platform
Windows Kernel Information Disclosure Vulnerability for Windows Server 2008 for x64-based Systems (KB4489876)Windows
Windows Kernel Information Disclosure Vulnerability for Windows Server 2008 for x86-based Systems (KB4489876)Windows
HID Information Disclosure Vulnerability for Windows Server 2008 for x64-based Systems (KB4489880)Windows
HID Information Disclosure Vulnerability for Windows Server 2008 for x86-based Systems (KB4489880)Windows
Windows Kernel Information Disclosure Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4489885)Windows
Windows Kernel Information Disclosure Vulnerability for Windows 7 for x86-based Systems (KB4489885)Windows
Windows Kernel Information Disclosure Vulnerability for Windows 7 for x64-based Systems (KB4489885)Windows
HID Information Disclosure Vulnerability for Windows 7 for x86-based Systems (KB4489878)Windows
HID Information Disclosure Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4489878)Windows
HID Information Disclosure Vulnerability for Windows 7 for x64-based Systems (KB4489878)Windows
Active Directory Elevation of Privilege Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4499151)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 8.1 for x64-based Systems (KB4499151)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 8.1 for x86-based Systems (KB4499151)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4499179)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4499179)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1803 for x86-based Systems (KB4499167)Windows
Active Directory Elevation of Privilege Vulnerability for Windows Server 2016 (1803) for x64-based Systems (KB4499167)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1803 for x64-based Systems (KB4499167)Windows
Active Directory Elevation of Privilege Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4499175)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 7 for x86-based Systems (KB4499175)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 7 for x64-based Systems (KB4499175)Windows
Active Directory Elevation of Privilege Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4499164)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 7 for x86-based Systems (KB4499164)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 7 for x64-based Systems (KB4499164)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4494440)Windows
Active Directory Elevation of Privilege Vulnerability for Windows Server 2016 for x64-based Systems (KB4494440)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4494440)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4499181)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4499181)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1809 for x86-based Systems (KB4494441)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1809 for x64-based Systems (KB4494441)Windows
Active Directory Elevation of Privilege Vulnerability for Windows Server 2019 for x64-based Systems (KB4494441)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1507 for x64-based Systems (KB4499154)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1507 for x86-based Systems (KB4499154)Windows
Active Directory Elevation of Privilege Vulnerability for Windows Server 2012 for x64-based Systems (KB4499171)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1903 for x86-based Systems (KB4497936)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1903 for x64-based Systems (KB4497936)Windows
Active Directory Elevation of Privilege Vulnerability for Windows Server 2012 for x64-based Systems (KB4499158)Windows
Active Directory Elevation of Privilege Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4499165)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 8.1 for x64-based Systems (KB4499165)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 8.1 for x86-based Systems (KB4499165)Windows
2019-07 Security Only Quality Update for Windows 7 for x86-based Systems (KB4507456)Windows
2019-07 Security Only Quality Update for Windows Server 2008 R2 for x64-based Systems (KB4507456)Windows
2019-07 Security Only Quality Update for Windows 7 for x64-based Systems (KB4507456)Windows
2019-07 Security Only Quality Update for Windows 8.1 for x64-based Systems (KB4507457)Windows
2019-07 Security Only Quality Update for Windows Server 2012 R2 for x64-based Systems (KB4507457)Windows
2019-07 Security Only Quality Update for Windows 8.1 for x86-based Systems (KB4507457)Windows
2019-07 Security Only Quality Update for Windows Server 2008 for x64-based Systems (KB4507461)Windows
2019-07 Security Only Quality Update for Windows Server 2008 for x86-based Systems (KB4507461)Windows
2019-07 Security Only Quality Update for Windows Server 2012 for x64-based Systems (KB4507464)Windows
2019-07 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4507455)Windows
2019-07 Cumulative Update for Windows 10 Version 1709 for x86-based Systems (KB4507455)Windows
2019-07 Security Monthly Quality Rollup for Windows 7 for x86-based Systems (KB4507449)Windows
2019-07 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB4507449)Windows
2019-07 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems (KB4507449)Windows
2019-07 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4507460)Windows
2019-07 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4507460)Windows
2019-07 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4507460)Windows
2019-07 Security Monthly Quality Rollup for Windows 8.1 for x86-based Systems (KB4507448)Windows
2019-07 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems (KB4507448)Windows
2019-07 Security Monthly Quality Rollup for Windows Server 2012 R2 for x64-based Systems (KB4507448)Windows
2019-07 Cumulative Update for Windows 10 Version 1703 for x86-based Systems (KB4507450)Windows
2019-07 Cumulative Update for Windows 10 Version 1703 for x64-based Systems (KB4507450)Windows
2019-07 Cumulative Update for Windows Server 2019 for x64-based Systems (KB4507469)Windows
2019-07 Cumulative Update for Windows 10 Version 1809 for x86-based Systems (KB4507469)Windows
2019-07 Cumulative Update for Windows 10 Version 1809 for x64-based Systems (KB4507469)Windows
2019-07 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB4507458)Windows
2019-07 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB4507458)Windows
2019-07 Cumulative Update for Windows 10 Version 1803 for x86-based Systems (KB4507435)Windows
2019-07 Cumulative Update for Windows 10 Version 1803 for x64-based Systems (KB4507435)Windows
2019-07 Cumulative Update for Windows Server 2016 (1803) for x64-based Systems (KB4507435)Windows
2019-07 Cumulative Update for Windows Server, version 1903 for x64-based Systems (KB4507453)Windows
2019-07 Cumulative Update for Windows 10 Version 1903 for x86-based Systems (KB4507453)Windows
2019-07 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4507453)Windows
2019-07 Security Monthly Quality Rollup for Windows Server 2008 for x64-based Systems (KB4507452)Windows
2019-07 Security Monthly Quality Rollup for Windows Server 2008 for x86-based Systems (KB4507452)Windows
2019-07 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB4507462)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4507450) (CVE-2019-0880)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4507450) (CVE-2019-0880)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4507450) (CVE-2019-0880)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4507450) (CVE-2019-0880)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-262872019-03 Security Only Quality Update for Windows Server 2008 for x64-based Systems (KB4489876)
PATCH-262882019-03 Security Only Quality Update for Windows Server 2008 for x86-based Systems (KB4489876)
PATCH-263102019-03 Security Monthly Quality Rollup for Windows Server 2008 for x64-based Systems (KB4489880)
PATCH-263112019-03 Security Monthly Quality Rollup for Windows Server 2008 for x86-based Systems (KB4489880)
PATCH-262892019-03 Security Only Quality Update for Windows Server 2008 R2 for x64-based Systems (KB4489885)
PATCH-262902019-03 Security Only Quality Update for Windows 7 for x86-based Systems (KB4489885)
PATCH-262912019-03 Security Only Quality Update for Windows 7 for x64-based Systems (KB4489885)
PATCH-263122019-03 Security Monthly Quality Rollup for Windows 7 for x86-based Systems (KB4489878)
PATCH-263132019-03 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems (KB4489878)
PATCH-263142019-03 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB4489878)
PATCH-266682019-05 Security Monthly Quality Rollup for Windows Server 2012 R2 for x64-based Systems (KB4499151)
PATCH-266692019-05 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems (KB4499151)
PATCH-266702019-05 Security Monthly Quality Rollup for Windows 8.1 for x86-based Systems (KB4499151)
PATCH-266842019-05 Cumulative Update for Windows 10 Version 1709 for x86-based Systems (KB4499179)
PATCH-266852019-05 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4499179)
PATCH-266862019-05 Cumulative Update for Windows 10 Version 1803 for x86-based Systems (KB4499167)
PATCH-266972019-05 Cumulative Update for Windows Server 2016 (1803) for x64-based Systems (KB4499167)
PATCH-266982019-05 Cumulative Update for Windows 10 Version 1803 for x64-based Systems (KB4499167)
PATCH-266552019-05 Security Only Quality Update for Windows Server 2008 R2 for x64-based Systems (KB4499175)(CVE-2019-0708)
PATCH-266562019-05 Security Only Quality Update for Windows 7 for x86-based Systems (KB4499175)(CVE-2019-0708)
PATCH-266572019-05 Security Only Quality Update for Windows 7 for x64-based Systems (KB4499175)(CVE-2019-0708)
PATCH-266742019-05 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems (KB4499164)(CVE-2019-0708)
PATCH-266752019-05 Security Monthly Quality Rollup for Windows 7 for x86-based Systems (KB4499164)(CVE-2019-0708)
PATCH-266762019-05 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB4499164)(CVE-2019-0708)
PATCH-266772019-05 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4494440)
PATCH-266782019-05 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4494440)
PATCH-266792019-05 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4494440)
PATCH-266992019-05 Cumulative Update for Windows 10 Version 1809 for x86-based Systems (KB4494441)
PATCH-267002019-05 Cumulative Update for Windows 10 Version 1809 for x64-based Systems (KB4494441)
PATCH-267012019-05 Cumulative Update for Windows Server 2019 for x64-based Systems (KB4494441)
PATCH-266802019-05 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB4499154)
PATCH-266812019-05 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB4499154)
PATCH-266712019-05 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB4499171)
PATCH-267032019-05 Cumulative Update for Windows 10 Version 1903 for x86-based Systems (KB4497936)
PATCH-267042019-05 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4497936)
PATCH-266522019-05 Security Only Quality Update for Windows Server 2012 for x64-based Systems (KB4499158)
PATCH-266492019-05 Security Only Quality Update for Windows Server 2012 R2 for x64-based Systems (KB4499165)
PATCH-266502019-05 Security Only Quality Update for Windows 8.1 for x64-based Systems (KB4499165)
PATCH-266512019-05 Security Only Quality Update for Windows 8.1 for x86-based Systems (KB4499165)
PATCH-269552019-07 Security Only Quality Update for Windows 7 for x86-based Systems (KB4507456) (CVE-2019-1132)
PATCH-269562019-07 Security Only Quality Update for Windows Server 2008 R2 for x64-based Systems (KB4507456) (CVE-2019-1132)
PATCH-269572019-07 Security Only Quality Update for Windows 7 for x64-based Systems (KB4507456) (CVE-2019-1132)
PATCH-269582019-07 Security Only Quality Update for Windows 8.1 for x64-based Systems (KB4507457) (CVE-2019-0880)
PATCH-269592019-07 Security Only Quality Update for Windows Server 2012 R2 for x64-based Systems (KB4507457) (CVE-2019-0880)
PATCH-269602019-07 Security Only Quality Update for Windows 8.1 for x86-based Systems (KB4507457) (CVE-2019-0880)
PATCH-269622019-07 Security Only Quality Update for Windows Server 2008 for x64-based Systems (KB4507461) (CVE-2019-1132)
PATCH-269632019-07 Security Only Quality Update for Windows Server 2008 for x86-based Systems (KB4507461) (CVE-2019-1132)
PATCH-269612019-07 Security Only Quality Update for Windows Server 2012 for x64-based Systems (KB4507464) (CVE-2019-0880)
PATCH-269902019-07 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4507455) (CVE-2019-0880)
PATCH-269912019-07 Cumulative Update for Windows 10 Version 1709 for x86-based Systems (KB4507455) (CVE-2019-0880)
PATCH-269742019-07 Security Monthly Quality Rollup for Windows 7 for x86-based Systems (KB4507449) (CVE-2019-1132)
PATCH-269752019-07 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB4507449) (CVE-2019-1132)
PATCH-269762019-07 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems (KB4507449) (CVE-2019-1132)
PATCH-269832019-07 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4507460) (CVE-2019-0880)
PATCH-269842019-07 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4507460) (CVE-2019-0880)
PATCH-269852019-07 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4507460) (CVE-2019-0880)
PATCH-269772019-07 Security Monthly Quality Rollup for Windows 8.1 for x86-based Systems (KB4507448) (CVE-2019-0880)
PATCH-269782019-07 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems (KB4507448) (CVE-2019-0880)
PATCH-269792019-07 Security Monthly Quality Rollup for Windows Server 2012 R2 for x64-based Systems (KB4507448) (CVE-2019-0880)
PATCH-269952019-07 Cumulative Update for Windows Server 2019 for x64-based Systems (KB4507469) (CVE-2019-0880)
PATCH-269962019-07 Cumulative Update for Windows 10 Version 1809 for x86-based Systems (KB4507469) (CVE-2019-0880)
PATCH-269972019-07 Cumulative Update for Windows 10 Version 1809 for x64-based Systems (KB4507469) (CVE-2019-0880)
PATCH-269862019-07 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB4507458) (CVE-2019-0880)
PATCH-269872019-07 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB4507458) (CVE-2019-0880)
PATCH-269922019-07 Cumulative Update for Windows 10 Version 1803 for x86-based Systems (KB4507435) (CVE-2019-0880)
PATCH-269932019-07 Cumulative Update for Windows 10 Version 1803 for x64-based Systems (KB4507435) (CVE-2019-0880)
PATCH-269942019-07 Cumulative Update for Windows Server 2016 (1803) for x64-based Systems (KB4507435) (CVE-2019-0880)
PATCH-269982019-07 Cumulative Update for Windows Server, version 1903 for x64-based Systems (KB4507453) (CVE-2019-0880)
PATCH-269992019-07 Cumulative Update for Windows 10 Version 1903 for x86-based Systems (KB4507453) (CVE-2019-0880)
PATCH-270002019-07 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4507453) (CVE-2019-0880)
PATCH-269812019-07 Security Monthly Quality Rollup for Windows Server 2008 for x64-based Systems (KB4507452) (CVE-2019-1132)
PATCH-269822019-07 Security Monthly Quality Rollup for Windows Server 2008 for x86-based Systems (KB4507452) (CVE-2019-1132)
PATCH-269802019-07 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB4507462) (CVE-2019-0880)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234