PT-2019-3047 · Microsoft · Windows

Zhong_Sf

·

Published

2019-08-13

·

Updated

2024-05-29

·

CVE-2019-1180

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows (affected versions not specified)
Description The issue is related to errors in handling objects in memory by the wcmsvc.dll library in the Windows operating system. This could allow an attacker to elevate their privileges and execute arbitrary code using a specially crafted application. A locally authenticated attacker could exploit this issue by running such an application.
Recommendations To resolve the issue, apply the security update that ensures the wcmsvc.dll properly handles objects in memory. As a temporary workaround, consider restricting access to the wcmsvc.dll library until the security update is applied. Avoid running specially crafted applications from untrusted sources to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2019-03029
CVE-2019-1180

Affected Products

Windows