PT-2019-2992 · Microsoft · Windows
Guopengfei
·
Published
2019-08-13
·
Updated
2024-07-03
·
CVE-2019-1228
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Windows (affected versions not specified)
Description
An information disclosure issue exists due to the Windows kernel's improper handling of objects in memory. This could allow an attacker to obtain information that could be used to further compromise the system by running a specially crafted application on an affected system. The issue does not directly allow code execution or user rights elevation but could facilitate further system compromise.
Recommendations
To resolve the issue, apply the update that corrects how the Windows kernel handles objects in memory.
As a temporary workaround, consider restricting access to sensitive system information until the update is applied.
Avoid running untrusted applications on affected systems to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows