PT-2019-3047 · Microsoft · Windows
Zhong_Sf
·
Published
2019-08-13
·
Updated
2024-05-29
·
CVE-2019-1180
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows (affected versions not specified)
Description
The issue is related to errors in handling objects in memory by the wcmsvc.dll library in the Windows operating system. This could allow an attacker to elevate their privileges and execute arbitrary code using a specially crafted application. A locally authenticated attacker could exploit this issue by running such an application.
Recommendations
To resolve the issue, apply the security update that ensures the wcmsvc.dll properly handles objects in memory.
As a temporary workaround, consider restricting access to the wcmsvc.dll library until the security update is applied.
Avoid running specially crafted applications from untrusted sources to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows