PT-2019-3590 · Microsoft · Internet Information Services+1

Netanel Ben-Simon

+1

·

Published

2019-10-08

·

Updated

2026-03-10

·

CVE-2019-1365

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Internet Information Services (affected versions not specified)
Description The issue is related to errors in handling objects in memory, which can be exploited by a remote attacker to elevate privileges. This allows an unprivileged function, run by a user, to execute code in the context of NT AUTHORITYsystem, thus escaping the sandbox. The vulnerability exists due to the failure to check the length of a buffer before copying memory to it.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2019-03799
CVE-2019-1365

Affected Products

Internet Information Services
Windows