CVE-2019-0707

Description

An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it.To exploit the vulnerability, in a local attack scenario, an attacker could run a specially crafted application to elevate the attackers privilege level, aka Windows NDIS Elevation of Privilege Vulnerability.

Risk Information

Base Score
6.9
MODERATE
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
0.249

Associated Vulnerability

VulnerabilityOS Platform
Active Directory Elevation of Privilege Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4499151)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 8.1 for x64-based Systems (KB4499151)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 8.1 for x86-based Systems (KB4499151)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4499179)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4499179)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1803 for x86-based Systems (KB4499167)Windows
Active Directory Elevation of Privilege Vulnerability for Windows Server 2016 (1803) for x64-based Systems (KB4499167)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1803 for x64-based Systems (KB4499167)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4494440)Windows
Active Directory Elevation of Privilege Vulnerability for Windows Server 2016 for x64-based Systems (KB4494440)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4494440)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4499181)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4499181)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1809 for x86-based Systems (KB4494441)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1809 for x64-based Systems (KB4494441)Windows
Active Directory Elevation of Privilege Vulnerability for Windows Server 2019 for x64-based Systems (KB4494441)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1507 for x64-based Systems (KB4499154)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1507 for x86-based Systems (KB4499154)Windows
Active Directory Elevation of Privilege Vulnerability for Windows Server 2012 for x64-based Systems (KB4499171)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1903 for x86-based Systems (KB4497936)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 10 Version 1903 for x64-based Systems (KB4497936)Windows
Active Directory Elevation of Privilege Vulnerability for Windows Server 2012 for x64-based Systems (KB4499158)Windows
Active Directory Elevation of Privilege Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4499165)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 8.1 for x64-based Systems (KB4499165)Windows
Active Directory Elevation of Privilege Vulnerability for Windows 8.1 for x86-based Systems (KB4499165)Windows
Jet Database Engine Remote Code Execution Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4499181)Windows
Jet Database Engine Remote Code Execution Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4499181)Windows
Jet Database Engine Remote Code Execution Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4499181)Windows
Jet Database Engine Remote Code Execution Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4499181)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-266682019-05 Security Monthly Quality Rollup for Windows Server 2012 R2 for x64-based Systems (KB4499151)
PATCH-266692019-05 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems (KB4499151)
PATCH-266702019-05 Security Monthly Quality Rollup for Windows 8.1 for x86-based Systems (KB4499151)
PATCH-266842019-05 Cumulative Update for Windows 10 Version 1709 for x86-based Systems (KB4499179)
PATCH-266852019-05 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4499179)
PATCH-266862019-05 Cumulative Update for Windows 10 Version 1803 for x86-based Systems (KB4499167)
PATCH-266972019-05 Cumulative Update for Windows Server 2016 (1803) for x64-based Systems (KB4499167)
PATCH-266982019-05 Cumulative Update for Windows 10 Version 1803 for x64-based Systems (KB4499167)
PATCH-266772019-05 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4494440)
PATCH-266782019-05 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4494440)
PATCH-266792019-05 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4494440)
PATCH-266992019-05 Cumulative Update for Windows 10 Version 1809 for x86-based Systems (KB4494441)
PATCH-267002019-05 Cumulative Update for Windows 10 Version 1809 for x64-based Systems (KB4494441)
PATCH-267012019-05 Cumulative Update for Windows Server 2019 for x64-based Systems (KB4494441)
PATCH-266802019-05 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB4499154)
PATCH-266812019-05 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB4499154)
PATCH-266712019-05 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB4499171)
PATCH-267032019-05 Cumulative Update for Windows 10 Version 1903 for x86-based Systems (KB4497936)
PATCH-267042019-05 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4497936)
PATCH-266522019-05 Security Only Quality Update for Windows Server 2012 for x64-based Systems (KB4499158)
PATCH-266492019-05 Security Only Quality Update for Windows Server 2012 R2 for x64-based Systems (KB4499165)
PATCH-266502019-05 Security Only Quality Update for Windows 8.1 for x64-based Systems (KB4499165)
PATCH-266512019-05 Security Only Quality Update for Windows 8.1 for x86-based Systems (KB4499165)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234