CVE-2019-1019

Description

A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an attacker could send a specially crafted authentication request, aka Microsoft Windows Security Feature Bypass Vulnerability.

Risk Information

Base Score
8.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
2.844

Associated Vulnerability

VulnerabilityOS Platform
Scripting Engine Memory Corruption Vulnerability for Windows Server 2019 for x64-based Systems (KB4503327)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1809 for x86-based Systems (KB4503327)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1809 for x64-based Systems (KB4503327)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4503284)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4503284)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1903 for x86-based Systems (KB4503293)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1903 for x64-based Systems (KB4503293)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4503267)Windows
Scripting Engine Memory Corruption Vulnerability for Windows Server 2016 for x64-based Systems (KB4503267)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4503267)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4503279)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4503279)Windows
Windows Kernel Information Disclosure Vulnerability for Windows 8.1 for x86-based Systems (KB4503290)Windows
Windows Kernel Information Disclosure Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4503290)Windows
Windows Kernel Information Disclosure Vulnerability for Windows 8.1 for x64-based Systems (KB4503290)Windows
Scripting Engine Memory Corruption Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4503276)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 8.1 for x86-based Systems (KB4503276)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 8.1 for x64-based Systems (KB4503276)Windows
Windows Kernel Information Disclosure Vulnerability for Windows Server 2008 for x64-based Systems (KB4503287)Windows
Windows Kernel Information Disclosure Vulnerability for Windows Server 2008 for x86-based Systems (KB4503287)Windows
Scripting Engine Memory Corruption Vulnerability for Windows Server 2008 for x64-based Systems (KB4503273)Windows
Scripting Engine Memory Corruption Vulnerability for Windows Server 2008 for x86-based Systems (KB4503273)Windows
Windows Kernel Information Disclosure Vulnerability for Windows Server 2012 for x64-based Systems (KB4503263)Windows
Scripting Engine Memory Corruption Vulnerability for Windows Server 2012 for x64-based Systems (KB4503285)Windows
Scripting Engine Memory Corruption Vulnerability for Windows Server 2016 (1803) for x64-based Systems (KB4503286)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1803 for x86-based Systems (KB4503286)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1803 for x64-based Systems (KB4503286)Windows
Windows Kernel Information Disclosure Vulnerability for Windows 7 for x64-based Systems (KB4503269)Windows
Windows Kernel Information Disclosure Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4503269)Windows
Windows Kernel Information Disclosure Vulnerability for Windows 7 for x86-based Systems (KB4503269)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 7 for x86-based Systems (KB4503292)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 7 for x64-based Systems (KB4503292)Windows
Scripting Engine Memory Corruption Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4503292)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1507 for x86-based Systems (KB4503291)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1507 for x64-based Systems (KB4503291)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4503279)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4503279)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4503279)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4503279)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-268752019-06 Cumulative Update for Windows Server 2019 for x64-based Systems (KB4503327)
PATCH-268762019-06 Cumulative Update for Windows 10 Version 1809 for x86-based Systems (KB4503327)
PATCH-268772019-06 Cumulative Update for Windows 10 Version 1809 for x64-based Systems (KB4503327)
PATCH-268702019-06 Cumulative Update for Windows 10 Version 1709 for x86-based Systems (KB4503284)
PATCH-268712019-06 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4503284)
PATCH-268782019-06 Cumulative Update for Windows 10 Version 1903 for x86-based Systems (KB4503293)
PATCH-268802019-06 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4503293)
PATCH-268632019-06 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4503267)
PATCH-268642019-06 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4503267)
PATCH-268652019-06 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4503267)
PATCH-268272019-06 Security Only Quality Update for Windows 8.1 for x86-based Systems (KB4503290)
PATCH-268282019-06 Security Only Quality Update for Windows Server 2012 R2 for x64-based Systems (KB4503290)
PATCH-268292019-06 Security Only Quality Update for Windows 8.1 for x64-based Systems (KB4503290)
PATCH-268362019-06 Security Monthly Quality Rollup for Windows Server 2012 R2 for x64-based Systems (KB4503276)
PATCH-268372019-06 Security Monthly Quality Rollup for Windows 8.1 for x86-based Systems (KB4503276)
PATCH-268382019-06 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems (KB4503276)
PATCH-268312019-06 Security Only Quality Update for Windows Server 2008 for x64-based Systems (KB4503287)
PATCH-268322019-06 Security Only Quality Update for Windows Server 2008 for x86-based Systems (KB4503287)
PATCH-268402019-06 Security Monthly Quality Rollup for Windows Server 2008 for x64-based Systems (KB4503273)
PATCH-268412019-06 Security Monthly Quality Rollup for Windows Server 2008 for x86-based Systems (KB4503273)
PATCH-268302019-06 Security Only Quality Update for Windows Server 2012 for x64-based Systems (KB4503263)
PATCH-268392019-06 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB4503285)
PATCH-268722019-06 Cumulative Update for Windows Server 2016 (1803) for x64-based Systems (KB4503286)
PATCH-268732019-06 Cumulative Update for Windows 10 Version 1803 for x86-based Systems (KB4503286)
PATCH-268742019-06 Cumulative Update for Windows 10 Version 1803 for x64-based Systems (KB4503286)
PATCH-268332019-06 Security Only Quality Update for Windows 7 for x64-based Systems (KB4503269)
PATCH-268342019-06 Security Only Quality Update for Windows Server 2008 R2 for x64-based Systems (KB4503269)
PATCH-268352019-06 Security Only Quality Update for Windows 7 for x86-based Systems (KB4503269)
PATCH-268422019-06 Security Monthly Quality Rollup for Windows 7 for x86-based Systems (KB4503292)
PATCH-268432019-06 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB4503292)
PATCH-268442019-06 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems (KB4503292)
PATCH-268662019-06 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB4503291)
PATCH-268672019-06 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB4503291)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234